Executive brief
A vulnerability in Google Chrome's InterestGroups component could allow a remote attacker to escape the browser's security sandbox. This component is part of the browser's ad-targeting and privacy features. If exploited, an attacker who has already gained control over a website's rendering process could potentially gain broader access to the underlying operating system and user data.
Technical details
An improper input validation vulnerability (CWE-20) exists in the InterestGroups component of Google Chrome. The flaw allows a remote attacker who has already achieved code execution within a compromised renderer process to bypass sandbox restrictions. By providing specially crafted untrusted input, the attacker can trigger a sandbox escape. This vulnerability is addressed in Chrome version 149.0.7827.53 for Windows, Mac, and Linux.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome version 149.0.7827.53 released to stable channel.
- 2026-06-04: disclosed: CVE-2026-10970 published.