Junglewise Threat Intelligence

CVE-2026-11158: Google Chrome sandbox escape in Downloads via AppleScript

CVE-2026-11158 · Severity: info · CVSS 6.2 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in the Downloads component of Google Chrome for macOS could allow a local attacker to bypass security restrictions. By using a specially crafted AppleScript command, an attacker could escape the browser's security sandbox, which is designed to isolate the browser from the rest of the operating system. This could lead to unauthorized access to the user's files or the ability to execute commands with higher privileges on the system.

Technical details

An improper input validation vulnerability (CWE-20) exists in the Downloads component of Google Chrome for macOS. The flaw stems from insufficient validation of untrusted input when processing AppleScript commands. A local attacker can exploit this by providing a specially crafted command to trigger a sandbox escape. Successful exploitation allows the attacker to break out of the Chromium sandbox environment and execute arbitrary code or access sensitive data on the host macOS system. The issue is resolved in Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53/54 released for Windows and Mac
  • 2026-06-04: disclosed: CVE-2026-11158 published

References

Related threats