Junglewise Threat Intelligence

CVE-2026-12034: Google Chrome improper input validation in Linux Toolkit Theming

CVE-2026-12034 · Severity: info · Published 2026-06-11

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A security vulnerability in its Linux version could allow a malicious file to bypass the browser's security 'sandbox,' which is designed to keep web content isolated from the rest of the computer. If exploited, an attacker who has already gained some control over the browser could potentially access the underlying operating system and user data.

Technical details

This vulnerability is classified as improper input validation (CWE-20) within the Linux Toolkit Theming component of Google Chrome. The flaw allows a remote attacker who has already achieved code execution within the sandboxed renderer process to escape the sandbox by providing a specially crafted malicious file. By bypassing the sandbox, the attacker can gain broader access to the host Linux system. The issue is resolved in Google Chrome version 149.0.7827.115 for Linux. Access to further technical details is currently restricted by the vendor to allow users time to update.

Affected products

  • Google Chrome prior to 149.0.7827.115

Timeline

  • 2026-06-02: disclosed: Reported by Google internal researchers
  • 2026-06-11: patched: Fixed in version 149.0.7827.115
  • 2026-06-11: advisory

References

Related threats