top of page
perceptive_background_267k.jpg

Integer overflow in QUIC in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a san…

Published:

30 July 2026 at 00:00:00

Alert date:

30 July 2026 at 22:07:35

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Zero-Day Vulnerabilities

CVE-2026-17673 is a high-severity integer overflow vulnerability in the QUIC protocol implementation within Google Chrome. The flaw affects all Chrome versions prior to 151.0.7922.72. A remote attacker who has already compromised the renderer process can exploit this vulnerability to potentially escape the Chrome sandbox. Exploitation requires delivering a crafted HTML page to the victim. The attack surface is remote, making it particularly dangerous in web browsing scenarios. Google has addressed the issue in the stable channel update released for desktop. The vulnerability has been rated High severity by the Chromium security team. Users are advised to update to Chrome 151.0.7922.72 or later immediately.

Technical details

Mitigation steps:

Affected products:

Google Chrome

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page