Junglewise Threat Intelligence

CVE-2026-12465: Google Chrome sandbox escape in Metrics

CVE-2026-12465 · Severity: high · CVSS 8.3 · Published 2026-06-17

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its metrics reporting component could allow a malicious website to bypass the browser's security sandbox. If exploited, an attacker who has already gained limited control over a browser process could potentially gain full access to the underlying operating system and user data.

Technical details

An object lifecycle issue exists in the Metrics component of Google Chrome prior to version 149.0.7827.155. The vulnerability is characterized as insufficient validation of untrusted input (CWE-20). A remote attacker can exploit this by enticing a user to visit a malicious HTML page. A successful exploit requires the attacker to have already compromised the renderer process; from that position, they can leverage this flaw to achieve a sandbox escape and execute code with higher privileges. Google has addressed this issue in the stable channel update for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 149.0.7827.155

Timeline

  • 2026-06-05: other: Reported to Google
  • 2026-06-16: patched: Stable channel update released
  • 2026-06-17: advisory: NVD publication date

References

Related threats