Junglewise Threat Intelligence

CVE-2026-10920: Google Chrome sandbox escape in WebShare on Mac

CVE-2026-10920 · Severity: info · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome for macOS could allow a malicious website to bypass security restrictions. If a user visits a specially crafted webpage, an attacker who has already gained limited control over the browser's rendering process could escape the 'sandbox'—a security layer designed to isolate the browser from the rest of the computer. This could lead to unauthorized access to the user's underlying operating system and data.

Technical details

An improper input validation vulnerability (CWE-20) exists in the WebShare component of Google Chrome for macOS. The flaw allows a remote attacker who has already achieved code execution within the sandboxed renderer process to bypass sandbox boundaries. By enticing a user to visit a malicious HTML page, the attacker can exploit the insufficient validation of untrusted input to interact with the host operating system. This vulnerability is specific to the Mac platform and was addressed in Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-04-02: disclosed: Reported by Google internal researchers
  • 2026-06-02: patched: Fixed in stable channel update 149.0.7827.53/54
  • 2026-06-04: advisory: NVD publication date

References

Related threats