


Perceptive Security
SOC/SIEM Consultancy

Type Confusion in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chro…
Published:
29 juli 2026 om 22:00:00
Alert date:
30 juli 2026 om 17:11:53
Source:
nvd.nist.gov
Web Technologies, Zero-Day Vulnerabilities
CVE-2026-17697 is a high-severity Type Confusion vulnerability in ANGLE (Almost Native Graphics Layer Engine) within Google Chrome. The flaw affects versions prior to 151.0.7922.72 and allows a remote attacker to potentially escape the browser sandbox by convincing a user to visit a crafted HTML page. ANGLE is the graphics abstraction layer used by Chrome to translate OpenGL ES calls to platform-specific graphics APIs. Type confusion vulnerabilities in graphics components can lead to memory corruption, enabling arbitrary code execution outside the sandbox. Google has rated this as High severity under the Chromium security severity scale. A patch was issued in Chrome stable channel version 151.0.7922.72. Users are strongly advised to update their Chrome browser immediately to mitigate the risk of exploitation.
Technical details
Mitigation steps:
Affected products:
Google Chrome prior to 151.0.7922.72
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-17697
https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html
https://issues.chromium.org/issues/517575864
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
