


Perceptive Security
SOC/SIEM Consultancy

Insufficient validation of untrusted input in WebAuthn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer proces…
Published:
29 July 2026 at 22:00:00
Alert date:
30 July 2026 at 20:07:35
Source:
nvd.nist.gov
Web Technologies, Zero-Day Vulnerabilities
CVE-2026-17990 is a vulnerability in Google Chrome's WebAuthn component caused by insufficient validation of untrusted input. The flaw affects Chrome versions prior to 151.0.7922.72 and allows a remote attacker who has already compromised the renderer process to potentially escape the sandbox. The attack vector involves a crafted PDF file. Although rated Low severity by Chromium's internal security scale, sandbox escapes carry significant real-world risk as they can lead to full system compromise. The vulnerability was patched in the Chrome stable channel update released in July 2026. Users are advised to update to Chrome 151.0.7922.72 or later to mitigate the risk.
Technical details
Mitigation steps:
Affected products:
Google Chrome
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-17990
https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html
https://issues.chromium.org/issues/520018012
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
