Junglewise Threat Intelligence

CVE-2026-17990: Google Chrome improper input validation in WebAuthn

CVE-2026-17990 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its WebAuthn component could allow a remote attacker who has already compromised the browser's rendering process to escape the security sandbox. If successful, this could allow the attacker to gain broader access to the underlying operating system via a specially crafted PDF file.

Technical details

An improper input validation vulnerability (CWE-20) exists in the WebAuthn component of Google Chrome. The flaw allows a remote attacker who has already achieved code execution within the sandboxed renderer process to bypass sandbox restrictions. This escape is triggered through the processing of a maliciously crafted PDF file. The vulnerability was addressed in Chrome version 151.0.7922.72. Google has classified the severity of this specific issue as Low.

Affected products

  • Google Chrome < 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in Chrome Stable Channel Update 151.0.7922.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats