Skip to content
GoogleCVE-2026-17768

Google Chrome: improper input validation

Critical9.6CVE-2026-17768 · Published Jul 30, 2026 · updated Aug 4, 2026

Insufficient validation of untrusted input in WebSockets in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

Google advisory

Affected versions

PackageAffectedFixed in
Chrome
Product
>= 151.0.7922.72, < 151.0.7922.72151.0.7922.72
Details and references

More Google advisories

All Google
Advisory
Google Chrome: spoofing
Medium4.3Jul 30
Google Chrome: remote attacker could bypass navigation restrictions
Medium6.5Jul 30
Google Chrome: remote attacker could potentially perform a sandbox escape
Critical9.6Jul 30
Google Chrome: spoofing
Medium4.3Jul 30
Google Chrome: use after free
High8.8Jul 30
Google Chrome: spoofing
Medium4.0Jul 30

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.