Description
Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a local attacker to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)
Published: 2026-07-30
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Use after free in the Views component of Google Chrome can lead a local attacker to escape the browser sandbox by manipulating a malicious file. The flaw occurs when stale memory is accessed after the object has been freed, causing the browser to perform privileged operations on corrupted data. The vulnerability is classified as high severity and could allow an attacker to gain elevated privileges or execute arbitrary code outside the sandbox environment.

Affected Systems

Google Chrome versions earlier than 151.0.7922.72 on Windows, macOS, and Linux installations are affected; all platforms that run the Chrome browser fall under the risk.

Risk and Exploitability

Based on the description, it is inferred that the likely attack vector is a local attacker opening a crafted file that the Chrome renderer processes, possibly through the file system or a network service. The CVSS score of 8.6 indicates high impact, while the EPSS score of less than 1% suggests that exploitation is currently rare but still plausible. The vulnerability is not listed in CISA KEV, meaning no widely documented attacks have been seen so far. If successful, the attacker can escape the sandbox and run code with the privileges of the user.

Generated by OpenCVE AI on August 2, 2026 at 07:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to version 151.0.7922.72 or later to receive the memory safety fix.
  • If an immediate update is not possible, block or delete any newly added file types or extensions that may be used to exploit rendering code, and consider applying stricter file handling policies.
  • Ensure Chrome sandboxing is enabled and monitor for anomalous processes that bypass the sandbox after opening potentially malicious files.

Generated by OpenCVE AI on August 2, 2026 at 07:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4710-1 chromium security update
Debian DSA Debian DSA DSA-6408-1 chromium security update
History

Thu, 30 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.9, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Thu, 30 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title chromium-browser: chromium-browser: Use after free in Views
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.9, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N'}

threat_severity

Important


Thu, 30 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 30 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Description Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a local attacker to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-30T15:37:36.401Z

Reserved: 2026-07-27T23:34:25.668Z

Link: CVE-2026-17699

cve-icon Vulnrichment

Updated: 2026-07-30T15:36:41.607Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-30T01:16:32.310

Modified: 2026-08-03T17:50:49.477

Link: CVE-2026-17699

cve-icon Redhat

Severity : Important

Publid Date: 2026-07-30T00:18:56Z

Links: CVE-2026-17699 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T07:30:03Z

Weaknesses