Executive brief
A vulnerability in Google Chrome for macOS could allow a remote attacker to escape the browser's security sandbox. This occurs if an attacker first compromises the browser's network process and then lures a user to a specially crafted website. Successfully exploiting this flaw could allow an attacker to gain unauthorized access to the underlying operating system, potentially compromising user data or system integrity.
Technical details
A race condition (CWE-362) exists in the Network component of Google Chrome for macOS. The vulnerability allows a remote attacker who has already achieved code execution within the compromised network process to escalate privileges and perform a sandbox escape. The attack is triggered when a user visits a maliciously crafted HTML page. This flaw is rated as High severity by Chromium. Users are advised to update to version 149.0.7827.103 or later to mitigate this risk.
Affected products
- Google Chrome prior to 149.0.7827.103
Timeline
- 2026-05-27: other: Reported to Google
- 2026-06-08: patched: Fixed in Stable Channel Update 149.0.7827.102/.103
- 2026-06-09: disclosed: CVE published