Description
Use after free in Ozone in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Published: 2026-07-30
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The CVE arises from a use‑after‑free bug in the Ozone graphical backend of Google Chrome. When a crafted HTML page is rendered, the attacker can trigger the freed memory usage to escape the browser's sandbox and potentially execute arbitrary code on the host system. This is a critical flaw, rated CVSS 9.6, that can compromise confidentiality, integrity, and availability if exploited.

Affected Systems

The vulnerability affects Google Chrome for desktop operating systems. All versions released prior to 151.0.7922.72 are susceptible. Users running Chrome in stable channel mode that have not applied the 151.0.7922.72 update or later are at risk.

Risk and Exploitability

The EPSS score is below 1%, indicating a very low but non‑zero probability of widespread exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a maliciously crafted HTML page opened in Chrome, where the attacker relies on the renderer process to trigger the sandbox escape. Because the flaw involves memory corruption, exploitation requires delivery of the crafted content and a Chrome instance that loads it, which is common in normal browsing scenarios. The high CVSS score reflects the severity of potential remote code execution if the sandbox is bypassed.

Generated by OpenCVE AI on August 3, 2026 at 12:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the patch that fixes the use‑after‑free (CWE‑416) bug in the Ozone backend by upgrading to Chrome 151.0.7922.72 or later.
  • Verify that Chrome’s sandbox is enabled to mitigate memory safety issues such as CWE‑825; this restricts process privileges and limits the impact of the flaw.
  • If an immediate update is not possible, configure Chrome Enterprise policy to restrict or disable renderer processes handling untrusted content until the security update is applied.

Generated by OpenCVE AI on August 3, 2026 at 12:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4710-1 chromium security update
Debian DSA Debian DSA DSA-6408-1 chromium security update
History

Sat, 01 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Use After Free in Ozone Allows Sandbox Escape via Crafted HTML Page chromium-browser: chromium-browser: Use after free in Ozone
Weaknesses CWE-825
References
Metrics threat_severity

None

threat_severity

Critical


Fri, 31 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title Use After Free in Ozone Allows Sandbox Escape via Crafted HTML Page

Fri, 31 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 30 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Description Use after free in Ozone in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-31T03:56:22.231Z

Reserved: 2026-07-27T23:34:15.589Z

Link: CVE-2026-17656

cve-icon Vulnrichment

Updated: 2026-07-30T20:33:42.942Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-30T01:16:27.530

Modified: 2026-08-06T00:30:24.850

Link: CVE-2026-17656

cve-icon Redhat

Severity : Critical

Publid Date: 2026-07-30T00:18:44Z

Links: CVE-2026-17656 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T12:45:03Z

Weaknesses