


Perceptive Security
SOC/SIEM Consultancy

Use after free in DataTransfer in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentia…
Published:
29 July 2026 at 22:00:00
Alert date:
30 July 2026 at 17:11:53
Source:
nvd.nist.gov
Web Technologies, Zero-Day Vulnerabilities, Operating Systems
CVE-2026-17692 is a high-severity use-after-free vulnerability in the DataTransfer component of Google Chrome on Windows. The flaw affects versions prior to 151.0.7922.72 and allows a remote attacker who has already compromised the renderer process to potentially escape the browser sandbox. Exploitation requires a crafted HTML page to trigger the vulnerability. The issue is classified as High severity by the Chromium security team. A patch was issued in Chrome stable channel update 151.0.7922.72. The vulnerability represents a significant risk as sandbox escapes can lead to full system compromise. Users are advised to update to the latest version of Chrome immediately.
Technical details
Mitigation steps:
Affected products:
Google Chrome on Windows (prior to 151.0.7922.72)
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-17692
https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html
https://issues.chromium.org/issues/517350808
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
