Description
Use after free in DevTools in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: Low)
Published: 2026-07-30
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a use‑after‑free in Chrome’s DevTools that an attacker can abuse by creating a crafted Chrome Extension. When a user installs the malicious extension, the extension code can execute arbitrary code within the sandbox that the extension runs in. The attacker could use this capability to perform further malicious actions such as exfiltrating data, installing additional malware, or escalating privileges relative to the sandboxed environment. The weakness is identified as CWE‑416 and CWE‑825.

Affected Systems

Affected systems include Google Chrome browsers running any version prior to 151.0.7922.72 released in July 2026. The security bulletin lists the affected channel as the stable desktop release. All installations of Chrome that have not yet applied the July 2026 stable update are vulnerable.

Risk and Exploitability

The CVSS score is 7.5, indicating a high severity. The EPSS score of less than 1% shows a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The attack would require the user to be convinced to install a malicious extension, which is a social‑engineering prerequisite. Therefore the risk is moderate; however, the potential for arbitrary code execution warrants prompt mitigation.

Generated by OpenCVE AI on August 2, 2026 at 06:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to the latest stable version, 151.0.7922.72 or newer, using the built‑in update mechanism.
  • Review installed extensions and remove any that were added recently or that are not from trusted publishers.
  • Disable the installation of extensions from unknown sources in Chrome’s settings to prevent accidental installation of malicious extensions.
  • Monitor system logs and user activity for signs of unauthorized extension installation or anomalous behavior.

Generated by OpenCVE AI on August 2, 2026 at 06:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4710-1 chromium security update
Debian DSA Debian DSA DSA-6408-1 chromium security update
History

Fri, 31 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title chromium-browser: chromium-browser: Use after free in DevTools
Weaknesses CWE-825
References
Metrics threat_severity

None

threat_severity

Low


Thu, 30 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 30 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Description Use after free in DevTools in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: Low)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-31T03:56:08.063Z

Reserved: 2026-07-27T23:35:14.821Z

Link: CVE-2026-17898

cve-icon Vulnrichment

Updated: 2026-07-30T16:22:23.441Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-30T01:16:53.840

Modified: 2026-08-03T17:34:47.880

Link: CVE-2026-17898

cve-icon Redhat

Severity : Low

Publid Date: 2026-07-30T00:19:51Z

Links: CVE-2026-17898 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T06:30:17Z

Weaknesses