Junglewise Threat Intelligence

CVE-2026-17995: Google Chrome out of bounds read in Dawn

CVE-2026-17995 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability exists in Google Chrome's Dawn component, which is responsible for handling modern web graphics. A remote attacker could exploit this by tricking a user into visiting a specially crafted website. If successful, the attacker could read sensitive information from the browser's memory, potentially leading to further exploitation or data exposure.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in Dawn, the WebGPU implementation in Google Chrome. The flaw is triggered when the browser processes a maliciously crafted HTML page, allowing a remote attacker to perform memory reads outside of intended buffers. This is a client-side vulnerability reachable over the network without prior authentication, though it requires user interaction (visiting a site). The issue was addressed in Google Chrome version 151.0.7922.72.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in Chrome Stable channel update 151.0.7922.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats