top of page
perceptive_background_267k.jpg

Heap buffer overflow in Color in Google Chrome on ChromeOS prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentia…

Published:

29 juli 2026 om 22:00:00

Alert date:

30 juli 2026 om 16:04:09

Source:

nvd.nist.gov

Click to open the original link from this advisory

Operating Systems, Web Technologies, Zero-Day Vulnerabilities

CVE-2026-17680 is a heap buffer overflow vulnerability in the Color component of Google Chrome on ChromeOS, affecting versions prior to 151.0.7922.72. The flaw allows a remote attacker who has already compromised the renderer process to potentially perform a sandbox escape via a specially crafted HTML page. The vulnerability is rated High severity by the Chromium security team. Successful exploitation requires a prior renderer compromise, making it a second-stage attack vector. Google has addressed the issue in Chrome version 151.0.7922.72 for ChromeOS. The vulnerability was publicly disclosed via NVD and the Chrome stable channel release blog. No active exploitation in the wild is currently mentioned, but the sandbox escape potential makes it critically important to patch.

Technical details

Mitigation steps:

Affected products:

Google Chrome on ChromeOS prior to 151.0.7922.72

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page