Executive brief
A vulnerability in Google Chrome's Chromoting component could allow an attacker to escape the browser's security sandbox. This component is used for remote desktop and screen sharing capabilities. If a user visits a specially crafted malicious website, an attacker who has already compromised the browser's rendering process could gain broader access to the underlying operating system, potentially leading to data theft or full system compromise.
Technical details
A sandbox escape vulnerability exists in the Chromoting component of Google Chrome due to insufficient validation of untrusted input. An attacker who has already achieved code execution within a compromised renderer process can exploit this flaw by directing the browser to a crafted HTML page. This allows the attacker to bypass the security boundaries of the Chromium sandbox and execute arbitrary commands with the privileges of the browser process. The issue is addressed in Google Chrome version 149.0.7827.53.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
- 2026-06-04: disclosed: CVE published in NVD.