Executive brief
A security vulnerability has been identified in Google Chrome for macOS that could allow a malicious website to bypass the browser's security sandbox. The sandbox is a critical defense layer designed to prevent malicious code from escaping the browser and accessing the rest of the computer. If successfully exploited, an attacker who has already compromised a browser tab could gain broader access to the underlying operating system, potentially leading to unauthorized data access or full system compromise.
Technical details
A use-after-free vulnerability exists in the USB component of Google Chrome for macOS. The flaw is triggered when the browser incorrectly manages memory during interactions with USB devices or related APIs. An attacker who has already achieved code execution within a compromised renderer process (e.g., via a separate memory corruption bug) can leverage this vulnerability to escape the Chromium sandbox. This is achieved by enticing a user to visit a specially crafted HTML page. Successful exploitation grants the attacker the privileges of the browser process on the host operating system. The issue is resolved in Chrome version 150.0.7871.47.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: advisory
- 2026-06-30: patched