« Back to list

CVE-2026-17661

Status: AnalyzedHigh (8.8)—

Use after free in Loader in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

🎯 ATT&CK techniques

How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.

Use-after-free (CWE-416) en Chrome con UI:R requiere que el usuario abra una página HTML maliciosa. La ejecución de código arbitrario en sandbox se logra mediante T1203 (explotación para ejecución en cliente). El impacto es T1059 (ejecución de comandos/código).

Inferred by our analysis agent from the official description, CVSS vector and CWE, and checked by a supervisor. May contain errors.

🛡️ ATT&CK mitigations that cover these techniques

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2026-17661",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-17661",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-07-30T00:00:00+00:00"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "chrome-cve-admin@google.com",
      "affectedData": [
        {
          "vendor": "Google",
          "product": "Chrome",
          "versions": [
            {
              "status": "affected",
              "version": "151.0.7922.72",
              "lessThan": "151.0.7922.72",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-07-30T01:16:28.090",
  "references": [
    {
      "url": "https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html",
      "tags": [
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "https://issues.chromium.org/issues/497451790",
      "tags": [
        "Permissions Required"
      ],
      "source": "chrome-cve-admin@google.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "chrome-cve-admin@google.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-416"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Use after free in Loader in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)"
    }
  ],
  "lastModified": "2026-08-10T14:13:26.117",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5306E563-AFD7-43CB-AFC8-CE1F449BA94C",
              "versionEndExcluding": "151.0.7922.72"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "chrome-cve-admin@google.com"
}