Executive brief
A security vulnerability exists in the Google Chrome web browser for Linux. This flaw could allow a remote attacker who has already compromised a browser tab to break out of the browser's security sandbox. If successful, an attacker could gain broader access to the underlying operating system, potentially leading to unauthorized data access or full system compromise.
Technical details
A vulnerability classified as 'Inappropriate Implementation' (CWE-20) exists in the Views component of Google Chrome for Linux. The flaw is rooted in insufficient validation of untrusted input. An attacker who has successfully compromised the renderer process (for example, via a separate memory corruption bug) can leverage this vulnerability via a crafted HTML page to bypass sandbox restrictions. This sandbox escape allows the attacker to execute code outside of the restricted browser environment on the host Linux system. The issue is resolved in version 149.0.7827.103 and later.
Affected products
- Google Chrome prior to 149.0.7827.103
Timeline
- 2026-05-27: disclosed: Reported to Google by internal/external researchers
- 2026-06-08: patched: Stable channel update released for Windows, Mac, and Linux
- 2026-06-09: advisory: NVD publication date