What is CVE-2026-17680?
A heap buffer overflow vulnerability in Color in Google Chrome on ChromeOS prior to version 151.0.7922.72 allowed a remote attacker who compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. Users are advised to update their browser to the latest version.
Azərbaycanca: Google Chrome-un ChromeOS üçün olan 151.0.7922.72 versiyasından əvvəlki versiyalarında rəng idarəetməsində "heap buffer overflow" zəifliyi aşkarlanıb. Bu, "renderer" prosesini ələ keçirmiş uzaqdan hücumçuya xüsusi hazırlanmış HTML səhifəsi vasitəsilə sandbox mühitindən qaçmağa imkan verə bilər. İstifadəçilərə brauzerlərini ən son versiyaya yeniləmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-119; shared vendor: Google
FAQ1
Which operating system is targeted by CVE-2026-17680?
This vulnerability specifically targets the Google Chrome browser running on ChromeOS.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.