CRITICAL 9.6 NVD

CVE-2026-17837

Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer proces

Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

Affected Products

References

Published: 2026-07-30 · Source: NVD · Feed updated: 2026-08-04
This critical severity vulnerability with a CVSS score of 9.6 was published on 2026-07-30 via NVD. Affected: google/chrome.

Risk Timeline

CVE Disclosed2026-07-30 · 4 days ago

Remediation Resources

Related Vulnerabilities

CVETitleSeverityCVSS
CVE-2026-17651Insufficient validation of untrusted input in Dawn in Google Chrome on Android pCRITICAL9.6
CVE-2026-17670Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a remoteCRITICAL9.6
CVE-2026-17671Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 15CRITICAL9.6
CVE-2026-17672Insufficient validation of untrusted input in Chromecast in Google Chrome prior CRITICAL9.6
CVE-2026-17673Integer overflow in QUIC in Google Chrome prior to 151.0.7922.72 allowed a remotCRITICAL9.6
CVE-2026-17675Out of bounds write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a rCRITICAL9.6
vulnfeed aggregates 9166 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.