Executive brief
A security vulnerability in Google Chrome for Mac could allow an attacker to bypass the browser's security sandbox. This sandbox is a critical layer of defense that prevents malicious websites from accessing the rest of your computer. If exploited, an attacker who has already gained control of a browser tab could potentially access sensitive user data or execute unauthorized commands on the underlying operating system.
Technical details
A race condition (CWE-362) exists in the Safe Browsing component of Google Chrome for macOS. The vulnerability is reachable by a remote attacker who has already achieved code execution within a compromised renderer process. By enticing a user to visit a specially crafted HTML page, the attacker can exploit improper synchronization in shared resources to escape the Chromium sandbox. This allows for a transition from the restricted renderer process to the more privileged browser process or the host operating system. The issue is resolved in Chrome version 149.0.7827.155.
Affected products
- Google Chrome prior to 149.0.7827.155
Timeline
- 2026-05-27: disclosed: Reported by Google researchers
- 2026-06-16: patched: Fixed in stable channel update 149.0.7827.155/.156
- 2026-06-17: advisory: NVD publication date