


Perceptive Security
SOC/SIEM Consultancy

Heap buffer overflow in Color in Google Chrome on ChromeOS prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentia…
Published:
30 July 2026 at 00:00:00
Alert date:
30 July 2026 at 18:04:09
Source:
nvd.nist.gov
Operating Systems, Web Technologies, Zero-Day Vulnerabilities
CVE-2026-17680 is a heap buffer overflow vulnerability in the Color component of Google Chrome on ChromeOS, affecting versions prior to 151.0.7922.72. The flaw allows a remote attacker who has already compromised the renderer process to potentially perform a sandbox escape via a specially crafted HTML page. The vulnerability is rated High severity by the Chromium security team. Successful exploitation requires a prior renderer compromise, making it a second-stage attack vector. Google has addressed the issue in Chrome version 151.0.7922.72 for ChromeOS. The vulnerability was publicly disclosed via NVD and the Chrome stable channel release blog. No active exploitation in the wild is currently mentioned, but the sandbox escape potential makes it critically important to patch.
Technical details
Mitigation steps:
Affected products:
Google Chrome on ChromeOS prior to 151.0.7922.72
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-17680
https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html
https://issues.chromium.org/issues/516486611
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
