What is CVE-2026-17653?
A use after free vulnerability in the Skia component of Google Chrome prior to version 151.0.7922.72 could allow a remote attacker who compromised the renderer process to perform a sandbox escape via a crafted HTML page. Users are advised to update their Chrome browser to the latest version immediately.
Azərbaycanca: Google Chrome-un 151.0.7922.72 versiyasına qədər olan Skia komponentində "use after free" (istifadədən sonra azad olunma) zəifliyi aşkarlanıb. Bu boşluq, renderer prosesini ələ keçirən uzaqdan hücumçuya xüsusi hazırlanmış HTML səhifəsi vasitəsilə sandbox-dan çıxmağa imkan verə bilər. İstifadəçilər Chrome brauzerlərini dərhal ən son versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-416; shared vendor: Google
FAQ2
In which component of Google Chrome was CVE-2026-17653 found?
This vulnerability was found in the Skia component of Google Chrome.
What can an attacker achieve by exploiting this vulnerability?
A remote attacker who compromised the renderer process can perform a sandbox escape via a crafted HTML page.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.