


Perceptive Security
SOC/SIEM Consultancy

Heap buffer overflow in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. …
Published:
29 juli 2026 om 22:00:00
Alert date:
30 juli 2026 om 20:07:35
Source:
nvd.nist.gov
Web Technologies, Zero-Day Vulnerabilities
CVE-2026-17758 describes a heap buffer overflow vulnerability in Dawn, the WebGPU implementation used in Google Chrome. The flaw affects Chrome versions prior to 151.0.7922.72 and could allow a remote attacker to potentially escape the browser sandbox by enticing a victim to visit a crafted HTML page. The vulnerability is rated Medium severity by the Chromium security team. Google addressed the issue in the stable channel update released for desktop. Heap buffer overflows in browser graphics components are particularly sensitive as they can be leveraged for memory corruption and code execution. The fix is included in Chrome 151.0.7922.72 and users are advised to update immediately. No active exploitation in the wild has been confirmed at this time based on available information.
Technical details
Mitigation steps:
Affected products:
Google Chrome
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-17758
https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html
https://issues.chromium.org/issues/503801946
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
