Junglewise Threat Intelligence

CVE-2026-12009: Google Chrome sandbox escape in Accessibility on macOS

CVE-2026-12009 · Severity: info · CVSS 9.8 · Published 2026-06-11

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A critical security vulnerability in the Accessibility component on macOS could allow a remote attacker to escape the browser's security sandbox. If exploited, this could allow an attacker to gain unauthorized access to the underlying operating system and user data after compromising a browser tab.

Technical details

A vulnerability exists in Google Chrome for macOS due to insufficient validation of untrusted input within the Accessibility component. This flaw allows a remote attacker who has already achieved code execution within a compromised renderer process to perform a sandbox escape. By enticing a user to visit a specially crafted HTML page, the attacker can leverage this input validation error to bypass the browser's security isolation and interact directly with the operating system. The issue is addressed in Chrome version 149.0.7827.115 for Mac.

Affected products

  • Google Chrome prior to 149.0.7827.115

Timeline

  • 2026-05-28: disclosed: Reported to Chrome by Google researchers
  • 2026-06-11: patched: Stable channel update released for Desktop
  • 2026-06-11: advisory: NVD publication date

References

Related threats