top of page
perceptive_background_267k.jpg

Insufficient validation of untrusted input in WebAuthn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer proces…

Published:

30 juli 2026 om 00:00:00

Alert date:

30 juli 2026 om 22:07:35

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Zero-Day Vulnerabilities

CVE-2026-17990 is a vulnerability in Google Chrome's WebAuthn component caused by insufficient validation of untrusted input. The flaw affects Chrome versions prior to 151.0.7922.72 and allows a remote attacker who has already compromised the renderer process to potentially escape the sandbox. The attack vector involves a crafted PDF file. Although rated Low severity by Chromium's internal security scale, sandbox escapes carry significant real-world risk as they can lead to full system compromise. The vulnerability was patched in the Chrome stable channel update released in July 2026. Users are advised to update to Chrome 151.0.7922.72 or later to mitigate the risk.

Technical details

Mitigation steps:

Affected products:

Google Chrome

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page