


Perceptive Security
SOC/SIEM Consultancy

Use after free in Ozone in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chro…
Published:
29 juli 2026 om 22:00:00
Alert date:
30 juli 2026 om 22:03:35
Source:
nvd.nist.gov
Web Technologies, Zero-Day Vulnerabilities
CVE-2026-17656 is a critical use-after-free vulnerability in the Ozone component of Google Chrome. The flaw affects versions prior to 151.0.7922.72 and allows a remote attacker to potentially escape the browser sandbox. Exploitation is possible via a specially crafted HTML page, meaning no user interaction beyond visiting a malicious page may be required. Google has assigned this vulnerability a Critical severity rating under the Chromium security severity scale. A patch was released in Chrome stable channel version 151.0.7922.72. The vulnerability is tracked by Chromium issue 523725277. Organizations and users running older versions of Chrome on desktop platforms are at risk. Sandbox escapes of this nature can lead to full system compromise if chained with additional exploits.
Technical details
Mitigation steps:
Affected products:
Google Chrome prior to 151.0.7922.72
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-17656
https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html
https://issues.chromium.org/issues/523725277
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
