Description
Use after free in Navigation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Published: 2026-07-30
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a use‑after‑free in the Navigation subsystem of Google Chrome. It allows a remote attacker who has already compromised the renderer process to invoke freed memory and potentially escape the sandbox. The primary impact is elevation of privilege that could lead to arbitrary code execution within the host system. The weakness is classified as CWE‑416.

Affected Systems

Affected clients run Google Chrome versions preceding 151.0.7922.72. The flaw manifests in any configuration where the renderer process may be exposed to untrusted HTML content. Users with older Chrome installations are at risk until they update to a patched release.

Risk and Exploitability

The CVSS score of 8.3 indicates high severity. However, the EPSS score of less than 1% implies that active exploitation is currently rare, and the vulnerability is not yet cataloged in CISA's known exploited vulnerabilities list. The likely attack path requires the attacker to first gain control of a renderer process, for example through a malicious web page, and then trigger the use‑after‑free to escape the sandbox. Once the sandbox is broken, arbitrary code could run with the privileges of the browser process.

Generated by OpenCVE AI on August 2, 2026 at 07:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 151.0.7922.72 or newer to apply the proprietary patch.
  • If an upgrade is not immediately feasible, configure the browser to run in a highly restricted sandbox mode, disabling the use of untrusted renderer processes.
  • Ensure that the operating system user account that runs Chrome has minimal privileges, and apply any available OS updates that strengthen sandbox isolation.

Generated by OpenCVE AI on August 2, 2026 at 07:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4710-1 chromium security update
Debian DSA Debian DSA DSA-6408-1 chromium security update
History

Sat, 01 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Use After Free in Chrome Renderer Enables Sandbox Escape chromium-browser: chromium-browser: Use after free in Navigation
Weaknesses CWE-825
References
Metrics threat_severity

None

threat_severity

Important


Fri, 31 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title Use After Free in Chrome Renderer Enables Sandbox Escape

Fri, 31 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 30 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Description Use after free in Navigation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-31T03:56:21.542Z

Reserved: 2026-07-27T23:34:15.801Z

Link: CVE-2026-17657

cve-icon Vulnrichment

Updated: 2026-07-30T20:23:26.052Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-30T01:16:27.640

Modified: 2026-08-06T00:27:49.567

Link: CVE-2026-17657

cve-icon Redhat

Severity : Important

Publid Date: 2026-07-30T00:18:44Z

Links: CVE-2026-17657 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T07:30:03Z

Weaknesses