Junglewise Threat Intelligence

CVE-2026-13909: Google Chrome sandbox escape in DevTools

CVE-2026-13909 · Severity: info · CVSS 6.5 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability in Google Chrome's developer tools could allow a malicious website to bypass the browser's security sandbox. If an attacker has already compromised the part of the browser that displays web pages, they could use this flaw to gain broader access to the underlying operating system. This could lead to unauthorized access to local files or the execution of malicious software on the user's computer.

Technical details

This vulnerability is classified as insufficient policy enforcement within the DevTools component of Google Chrome. The flaw allows a remote attacker who has already achieved code execution within a compromised renderer process to escalate their privileges and perform a sandbox escape. By enticing a user to visit a specially crafted HTML page, the attacker can exploit the lack of strict policy checks in DevTools to interact with higher-privileged browser processes. This bypasses the security boundaries intended to isolate web content from the host operating system. The issue is resolved in Chrome version 150.0.7871.47 and later.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats