THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-17768 (CRITICAL 9.6) — Insufficient validation of untrusted input in WebSockets in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

[NVD] CVE-2026-17768 (CRITICAL 9.6) — Insufficient validation of untrusted input in WebSockets in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

mednvdPublished 2026-07-30

CVE-2026-17768 CVSS: 9.6 CRITICAL Published: 2026-07-30T01:16:39.990

Insufficient validation of untrusted input in WebSockets in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-17768