top of page
perceptive_background_267k.jpg

Use after free in Ozone in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chro…

Published:

29 juli 2026 om 22:00:00

Alert date:

30 juli 2026 om 22:03:35

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Zero-Day Vulnerabilities

CVE-2026-17656 is a critical use-after-free vulnerability in the Ozone component of Google Chrome. The flaw affects versions prior to 151.0.7922.72 and allows a remote attacker to potentially escape the browser sandbox. Exploitation is possible via a specially crafted HTML page, meaning no user interaction beyond visiting a malicious page may be required. Google has assigned this vulnerability a Critical severity rating under the Chromium security severity scale. A patch was released in Chrome stable channel version 151.0.7922.72. The vulnerability is tracked by Chromium issue 523725277. Organizations and users running older versions of Chrome on desktop platforms are at risk. Sandbox escapes of this nature can lead to full system compromise if chained with additional exploits.

Technical details

Mitigation steps:

Affected products:

Google Chrome prior to 151.0.7922.72

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page