Junglewise Threat Intelligence

CVE-2026-13025: Google Chrome race condition in DevTools sandbox escape

CVE-2026-13025 · Severity: info · CVSS 8.8 · Published 2026-06-24

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser for accessing the internet and internal applications. A security flaw in the browser's developer tools (DevTools) could allow a malicious website to bypass the browser's security 'sandbox.' If exploited, an attacker could gain unauthorized access to the underlying operating system, potentially leading to the theft of sensitive data or the installation of malware on the user's computer.

Technical details

A race condition exists in the DevTools component of Google Chrome prior to version 149.0.7827.197. The vulnerability is characterized as insufficient validation of untrusted input (CWE-20). An attacker who has already achieved code execution within the sandboxed renderer process can exploit this race condition via a specially crafted HTML page to escape the sandbox and execute arbitrary code on the host system. This is a high-severity flaw that breaks a fundamental security boundary of the browser. Google has released a patch in version 149.0.7827.197 for Windows and Mac, and 149.0.7827.196 for Linux.

Affected products

  • Google Chrome prior to 149.0.7827.197

Timeline

  • 2026-05-30: disclosed: Reported to Google by internal/external researchers
  • 2026-06-23: patched: Stable channel update released
  • 2026-06-24: advisory: NVD publication date

References

Related threats