


Perceptive Security
SOC/SIEM Consultancy

Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer proc…
Published:
30 July 2026 at 00:00:00
Alert date:
30 July 2026 at 22:07:35
Source:
nvd.nist.gov
Web Technologies, Zero-Day Vulnerabilities
CVE-2026-17672 is a high-severity vulnerability in Google Chrome's Chromecast component affecting versions prior to 151.0.7922.72. The flaw stems from insufficient validation of untrusted input, allowing a remote attacker who has already compromised the renderer process to potentially escape the browser sandbox. Exploitation requires a victim to visit a specially crafted HTML page. The vulnerability is classified as a sandbox escape, a critical class of bug that can lead to full system compromise beyond the browser environment. Google has addressed the issue in Chrome 151.0.7922.72. The Chromium security team rated this as High severity. The vulnerability is currently undergoing analysis on the NVD. No active exploitation has been confirmed at this time, but sandbox escapes following renderer compromise are considered high-risk attack chains.
Technical details
Mitigation steps:
Affected products:
Google Chrome
Chromecast
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-17672
https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html
https://issues.chromium.org/issues/513375270
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
