Junglewise Threat Intelligence

CVE-2026-18017: Google Chrome use after free in Dawn

CVE-2026-18017 · Severity: info · Published 2026-07-30

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its Dawn component could allow a remote attacker to execute unauthorized code on a user's computer if they visit a specially crafted website. While the attack is limited to the browser's security sandbox, it could still lead to further exploitation or disruption of the user's browsing session.

Technical details

A use-after-free (UAF) vulnerability exists in the Dawn component of Google Chrome prior to version 151.0.7922.72. Dawn is the implementation of the WebGPU standard in Chromium. The flaw is triggered when the browser incorrectly manages memory during the processing of a specially crafted HTML page. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious website, potentially leading to arbitrary code execution within the browser's sandbox environment. Google has addressed this issue in the stable channel update to version 151.0.7922.72.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: advisory: Google released a stable channel update addressing the issue.
  • 2026-07-30: disclosed: CVE published in NVD.

References

Related threats