Junglewise Threat Intelligence

CVE-2026-17987: Google Chrome sandbox escape in Notifications via PDF

CVE-2026-17987 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability exists in Google Chrome's notification system that could allow a remote attacker to bypass security protections. If an attacker has already compromised the browser's rendering process, they could use a specially crafted PDF file to escape the 'sandbox'—a security layer designed to keep malicious code from affecting the rest of the computer. This could potentially lead to unauthorized access to the underlying operating system.

Technical details

An improper input validation vulnerability (CWE-20) exists in the Notifications component of Google Chrome. The flaw allows a remote attacker who has already achieved code execution within a compromised renderer process to escalate privileges and perform a sandbox escape. The attack vector involves the processing of a maliciously crafted PDF file. Google has addressed this issue in version 151.0.7922.72 for Windows, Mac, and Linux. Chromium developers have classified this as a Low severity issue.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in version 151.0.7922.72
  • 2026-07-30: disclosed

References

Related threats