Executive brief
Google Chrome is a widely used web browser. A security vulnerability in the Windows version of the browser could allow a remote attacker to bypass security protections (sandbox escape) if they have already compromised the browser's rendering process. This could potentially allow an attacker to gain broader access to the underlying operating system after a user visits a malicious website.
Technical details
This vulnerability is classified as an 'Inappropriate implementation' within the Views component of Google Chrome for Windows. The flaw allows an attacker who has already achieved code execution within the sandboxed renderer process to escape that sandbox and interact with the host operating system. The attack vector involves a remote attacker enticing a user to visit a specially crafted HTML page. This issue was addressed in Google Chrome version 149.0.7827.115 for Windows.
Affected products
- Google Chrome prior to 149.0.7827.115
Timeline
- 2026-05-30: disclosed: Reported to Google by internal researchers
- 2026-06-11: patched: Stable channel update released
- 2026-06-11: advisory: NVD publication date