Executive brief
A security vulnerability exists in Google Chrome's Serial API, which allows the browser to communicate with hardware devices. An attacker who has already partially compromised the browser's content rendering process could use this flaw to break out of the security sandbox. If successful, this could allow the attacker to gain broader access to the underlying operating system and user data.
Technical details
This vulnerability is classified as insufficient policy enforcement (CWE-20) within the Serial API component of Google Chrome. The flaw allows a remote attacker to escalate their privileges from a compromised renderer process to the browser process, effectively achieving a sandbox escape. The attack requires the victim to visit a specially crafted HTML page, and the attacker must have already achieved code execution within the renderer process (typically via a separate vulnerability). The issue was addressed in Google Chrome version 150.0.7871.47.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched