Executive brief
A security vulnerability in Google Chrome for macOS could allow a malicious website to break out of the browser's security sandbox. This sandbox is designed to keep web content isolated from the rest of your computer; if bypassed, an attacker could potentially gain unauthorized access to your files or system. Users should update to the latest version of Chrome to protect their data and operations.
Technical details
A race condition (CWE-362) exists in the Updater component of Google Chrome for macOS. The vulnerability allows a remote attacker who has already compromised the renderer process to escape the browser sandbox by enticing a user to visit a specially crafted HTML page. This is classified as an 'Inappropriate implementation' in the Updater. Successful exploitation could lead to full system compromise by bypassing the security boundaries that normally isolate web content. The issue is resolved in Chrome version 149.0.7827.155.
Affected products
- Google Chrome prior to 149.0.7827.155
Timeline
- 2026-06-08: other: Reported to Google
- 2026-06-16: patched: Stable channel update released
- 2026-06-17: advisory: NVD publication date