Executive brief
Google Chrome's Headless mode, which is often used for automated web testing and server-side web processing, contains a security flaw. An attacker who has already gained control over a website's rendering process could use this vulnerability to break out of the browser's security sandbox. This could allow them to access the underlying operating system, potentially leading to data theft or full system compromise.
Technical details
A vulnerability exists in the Headless implementation of Google Chrome due to inappropriate policy enforcement. A remote attacker who has already compromised the renderer process can exploit this flaw via a specially crafted HTML page to perform a sandbox escape. This allows the attacker to execute code outside of the restricted browser environment on the host operating system. The issue is addressed in Google Chrome version 149.0.7827.115 for Windows and Mac, and 149.0.7827.114 for Linux.
Affected products
- Google Chrome prior to 149.0.7827.115
Timeline
- 2026-05-28: disclosed: Reported to Google by internal researchers.
- 2026-06-11: patched: Stable channel update released.
- 2026-06-11: advisory: NVD publication date.