


Perceptive Security
SOC/SIEM Consultancy

Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape vi…
Published:
29 juli 2026 om 22:00:00
Alert date:
30 juli 2026 om 22:03:35
Source:
nvd.nist.gov
Web Technologies, Zero-Day Vulnerabilities
CVE-2026-17655 is a critical vulnerability in Google Chrome's ANGLE graphics library affecting versions prior to 151.0.7922.72. The flaw stems from insufficient validation of untrusted input within the ANGLE component. A remote attacker could exploit this vulnerability by enticing a user to visit a specially crafted HTML page. Successful exploitation could result in a sandbox escape, potentially allowing the attacker to execute code outside the browser's security sandbox. Google has rated this vulnerability as Critical severity. A fix has been released in Chrome stable channel version 151.0.7922.72. Users are strongly advised to update their Chrome browser immediately to mitigate the risk.
Technical details
Mitigation steps:
Affected products:
Google Chrome
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-17655
https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html
https://issues.chromium.org/issues/522556145
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
