SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-17947

CRITICAL · CVSS 9.6 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

A use-after-free vulnerability in the WebSockets component of Google Chrome versions prior to 151.0.7922.72 allows remote attackers to execute arbitrary code, potentially leading to a sandbox escape through a specially crafted HTML page. Organizations using affected versions of Chrome should prioritize updates to mitigate the risk of exploitation, given the critical severity rating of 9.6. This vulnerability poses a significant threat to users who rely on Chrome for secure browsing.

CVE
CVE-2026-17947
Severity
CRITICAL
CVSS
9.6
EPSS
0.26%
Chrome

Original NVD Description

Use after free in WebSockets in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

Related CVEs

Other vulnerabilities affecting the same vendor(s)