Executive brief
A security vulnerability exists in the New Tab Page of the Google Chrome web browser. If an attacker has already partially compromised the browser's internal processes, they could use this flaw to bypass security 'sandboxes' that normally keep web content isolated from the rest of the computer. This could allow an attacker to gain broader access to the underlying operating system and user data.
Technical details
A vulnerability classified as improper input validation (CWE-20) exists in the New Tab Page component of Google Chrome. The flaw allows a remote attacker who has already achieved code execution within a compromised renderer process to bypass sandbox restrictions via a specially crafted HTML page. By escaping the sandbox, the attacker can potentially execute arbitrary code with the privileges of the browser process on the host operating system. This issue was addressed in Chrome version 149.0.7827.103.
Affected products
- Google Chrome prior to 149.0.7827.103
Timeline
- 2026-05-16: disclosed: Reported by Google internal researchers
- 2026-06-08: patched: Fixed in stable channel update 149.0.7827.102/.103
- 2026-06-09: advisory: NVD publication date