THREAT OPS › Threat News › [NVD] CVE-2026-17768 (CRITICAL 9.6) — Insufficient validation of untrusted input in WebSockets in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
[NVD] CVE-2026-17768 (CRITICAL 9.6) — Insufficient validation of untrusted input in WebSockets in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-17768 CVSS: 9.6 CRITICAL Published: 2026-07-30T01:16:39.990
Insufficient validation of untrusted input in WebSockets in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Indicators of compromise
- CVE-2026-17768cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-17768