Description
Use after free in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-07-30
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A use‑after‑free vulnerability in the DevTools front‑end of Google Chrome allows a remote attacker to execute arbitrary code inside the browser’s sandbox when a malicious HTML page is loaded. The flaw arises after DevTools frees an object that is still in use, enabling tampered memory and code execution. While Chromium rates it as medium severity, the potential for full control within the browser process represents a serious threat.

Affected Systems

The issue affects all versions of Google Chrome earlier than 151.0.7922.72 on every platform that ships the Chromium code base, including Windows, macOS, Linux and Chrome OS. The vulnerability is confined to the browser itself and requires that DevTools be open when the attacker’s malicious content is viewed.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity, but the EPSS score of <1% indicates a very low likelihood of active exploitation, and the flaw is not listed in CISA’s KEV catalog. An attacker must lure a user to open a specially crafted page while DevTools is active, which provides a path to run code within the sandbox. While the flaw does not immediately escape the sandbox, compromise of the browser process could lead to wider system compromise.

Generated by OpenCVE AI on August 2, 2026 at 06:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 151.0.7922.72 or later.
  • On managed devices, restrict or disable DevTools via group policy or device management settings.
  • Maintain a strict web content policy, keep all browser extensions and system security tools updated, and educate users to avoid opening untrusted pages while DevTools is enabled.

Generated by OpenCVE AI on August 2, 2026 at 06:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4710-1 chromium security update
Debian DSA Debian DSA DSA-6408-1 chromium security update
History

Thu, 30 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Thu, 30 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title chromium-browser: chromium-browser: Use after free in DevTools
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H'}

threat_severity

Moderate


Thu, 30 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 30 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Description Use after free in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-31T03:56:08.780Z

Reserved: 2026-07-27T23:35:14.385Z

Link: CVE-2026-17896

cve-icon Vulnrichment

Updated: 2026-07-30T16:22:50.509Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-30T01:16:53.633

Modified: 2026-08-03T17:35:01.583

Link: CVE-2026-17896

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-30T00:19:51Z

Links: CVE-2026-17896 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T06:30:17Z

Weaknesses