CVE detail
CVE-2026-17656
Use after free in Ozone in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 16.1 · diversity 16.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 4
- within the 30d window
- Peak daily
- 4
- highest bucket
Evidence
Source links by recency
4 source links · newest first
- ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More StoriesThe Hacker News
rrying out an AI-enabled autonomous hacking campaign, targeting infrastructure using seven vulnerabilities in Langflow (CVE-2026-33017), n8n (CVE-2026-21858, CVE-2025-68613), Citrix NetScaler (CVE-2026-3055), Apache Tomcat (CVE-2026-34486), Marimo Notebook (CVE-2026-39987), Palo Alto Networks PAN-OS (CVE-2026-0300), and Microsoft Windows IKE Extensions
newsthehackernews.comJul 30, 2026, 3:25 PM - Google Releases Patches for 370 Vulnerabilities in Chrome 151Infosecurity Magazine
een May 18 and June 14, 2026. The critical vulnerabilities, identified by their respective CVE numbers, are as follows: CVE-2026-17650: Use after free in Compositing (reported on May 18, 2026) CVE-2026-17651: Insufficient validation of untrusted input in Dawn (reported on May 28, 2026) CVE-2026-17652: Use after free in Views (reported on June 2, 2026)
newswww.infosecurity-magazine.comJul 30, 2026, 9:15 AM - https://issues.chromium.org/issues/523725277issues.chromium.org
No excerpt available.
Exploitissues.chromium.orgJul 30, 2026, 1:16 AM - https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.htmlchromereleases.googleblog.com
No excerpt available.
Vendor Advisorychromereleases.googleblog.comJul 30, 2026, 1:16 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-19560CVSS 8.8 · High
Use after free in Blink in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security s…
- CVE-2026-19559CVSS 8.8 · High
Use after free in HTML in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security se…
- CVE-2026-19558CVSS 7.5 · High
Use after free in Extensions in Google Chrome prior to 151.0.7922.137 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a…
- CVE-2026-19557CVSS 8.3 · High
Use after free in TabStrip in Google Chrome on Mac prior to 151.0.7922.137 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox esca…
- CVE-2026-19556CVSS 8.8 · High
Use after free in V8 in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security seve…
- CVE-2026-19176CVSS 7.5 · High
Use after free in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a…