Integer overflow in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted… (CVE-2026-17881)
Integer overflow in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
AI Analysis
Technical Summary
CVE-2026-17881 is an integer overflow vulnerability in the WebXR implementation of Google Chrome before version 151.0.7922.72. Exploitation involves a remote attacker delivering a specially crafted HTML page that triggers the overflow, enabling arbitrary code execution inside the browser's sandbox. The vulnerability is recognized as medium severity by the Chromium security team. No CVSS score is available, and no vendor advisory or patch links are provided in the data. The vulnerability does not affect cloud services and no known active exploits have been reported.
Potential Impact
Successful exploitation could allow remote code execution within the sandboxed environment of the browser, potentially leading to unauthorized actions or compromise of the browser process. However, the impact is limited by sandbox containment, and no active exploitation has been observed.
Mitigation Recommendations
A fix is available in Google Chrome version 151.0.7922.72 and later. Users and administrators should update to this version or a later one to remediate the vulnerability. Since this is a client-side browser vulnerability, updating the browser is the primary mitigation step. Patch status is confirmed by the version cutoff stated in the description.
Integer overflow in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted… (CVE-2026-17881)
Description
Integer overflow in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVSS v3.1
Score 8.8high
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-17881 is an integer overflow vulnerability in the WebXR implementation of Google Chrome before version 151.0.7922.72. Exploitation involves a remote attacker delivering a specially crafted HTML page that triggers the overflow, enabling arbitrary code execution inside the browser's sandbox. The vulnerability is recognized as medium severity by the Chromium security team. No CVSS score is available, and no vendor advisory or patch links are provided in the data. The vulnerability does not affect cloud services and no known active exploits have been reported.
Potential Impact
Successful exploitation could allow remote code execution within the sandboxed environment of the browser, potentially leading to unauthorized actions or compromise of the browser process. However, the impact is limited by sandbox containment, and no active exploitation has been observed.
Mitigation Recommendations
A fix is available in Google Chrome version 151.0.7922.72 and later. Users and administrators should update to this version or a later one to remediate the vulnerability. Since this is a client-side browser vulnerability, updating the browser is the primary mitigation step. Patch status is confirmed by the version cutoff stated in the description.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-pqxg-9927-553c
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-17881"]
- Ecosystems
- []
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a6ae5149c2644c7f8980cb8
Added to database: 07/30/2026, 05:45:56 UTC
Last enriched: 07/30/2026, 06:04:49 UTC
Last updated: 07/31/2026, 02:51:53 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.