Description
Use after free in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-07-30
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Use‑after‑free in the Dawn rendering engine in Google Chrome versions before 151.0.7922.72 allows a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. The flaw arises when the browser accesses freed memory after a rendering operation, which can lead to arbitrary code execution within the confined sandbox of the browser process.

Affected Systems

Google Chrome users running any version earlier than 151.0.7922.72 on the stable channel are affected. The vulnerability appears in the Dawn component of the browser and applies to all platforms that run the stable channel of Chrome.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity issue that can compromise the integrity of the browsing sandbox. However, the EPSS score is reported as less than 1%, suggesting that exploitation is currently rare. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a malicious or compromised web page that is rendered by the browser, leading to remote code execution in the sandboxed environment.

Generated by OpenCVE AI on August 4, 2026 at 11:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to version 151.0.7922.72 or later, which includes the patch for the use‑after‑free flaw in Dawn.
  • Ensure that automatic updates for Chrome are enabled so that future security releases are applied promptly.
  • Implement strong content security policies that restrict the execution of scripts originating from sandboxed iframes or other untrusted content.

Generated by OpenCVE AI on August 4, 2026 at 11:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4710-1 chromium security update
Debian DSA Debian DSA DSA-6408-1 chromium security update
History

Sat, 01 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome's Dawn Rendering Engine for Remote Code Execution chromium-browser: chromium-browser: Use after free in Dawn
References
Metrics threat_severity

None

threat_severity

Low


Fri, 31 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome's Dawn Rendering Engine for Remote Code Execution

Thu, 30 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 30 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Description Use after free in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-31T03:55:39.868Z

Reserved: 2026-07-27T23:37:19.137Z

Link: CVE-2026-18017

cve-icon Vulnrichment

Updated: 2026-07-30T12:42:12.304Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-30T01:17:06.500

Modified: 2026-07-31T04:17:19.150

Link: CVE-2026-18017

cve-icon Redhat

Severity : Low

Publid Date: 2026-07-30T00:26:09Z

Links: CVE-2026-18017 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T12:00:10Z

Weaknesses