Executive brief
Google Chrome is a widely used web browser. A vulnerability in the Linux version of the browser could allow a malicious website to bypass the security sandbox, which is the primary layer of defense that prevents web content from interacting with the rest of the computer. If exploited, this could allow an attacker to gain unauthorized access to the underlying operating system, potentially leading to data theft or further system compromise.
Technical details
A vulnerability exists in the Sandbox component of Google Chrome for Linux due to insufficient policy enforcement. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to bypass sandbox restrictions and execute code or perform actions outside of the restricted browser environment. This issue is specific to the Linux platform and was addressed in version 149.0.7827.53. The Chromium project has assigned this a 'Low' severity rating.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released for Linux
- 2026-06-05: disclosed: CVE published by NVD