Description
Use after free in Media in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-07-30
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is a use‑after‑free in Chrome’s media handling code. After the renderer process has already been compromised, a crafted HTML page can trigger a freed memory region to be reused, potentially breaking the browser sandbox isolation. This would allow attacker supplied code to run with higher privileges, endangering confidentiality, integrity, and availability of the host system. The Chromium team rates this Medium severity, but the CVSS score of 9.6 indicates a very high impact.

Affected Systems

Google Chrome browsers older than version 151.0.7922.72 are affected. The issue is triggered only when the renderer process is already compromised during page rendering.

Risk and Exploitability

The CVSS score of 9.6 shows a very high severity, while the EPSS score of less than 1% indicates a low overall probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. An attacker would need to provide a crafted HTML page that targets a renderer that has already been compromised; after exploitation the sandbox could be escaped, giving the attacker the ability to execute arbitrary code.

Generated by OpenCVE AI on August 2, 2026 at 06:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 151.0.7922.72 or later.
  • Ensure the renderer process runs with the default sandbox enabled and that no extensions or policies disable or weaken sandbox enforcement.
  • If possible, restrict loading of untrusted media content or limit access to the renderer from untrusted origins via browser policy or extensions.

Generated by OpenCVE AI on August 2, 2026 at 06:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4710-1 chromium security update
Debian DSA Debian DSA DSA-6408-1 chromium security update
History

Fri, 31 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.0, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Fri, 31 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title chromium-browser: chromium-browser: Use after free in Media
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 9.0, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H'}

threat_severity

Moderate


Thu, 30 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 30 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Description Use after free in Media in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-31T14:00:20.249Z

Reserved: 2026-07-27T23:34:49.654Z

Link: CVE-2026-17804

cve-icon Vulnrichment

Updated: 2026-07-31T14:00:14.217Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-30T01:16:43.847

Modified: 2026-08-03T17:54:54.947

Link: CVE-2026-17804

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-30T00:19:26Z

Links: CVE-2026-17804 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T07:00:07Z

Weaknesses