Executive brief
A security vulnerability has been identified in Google Chrome for Windows that could allow an attacker to bypass the browser's security sandbox. Chrome uses a sandbox to isolate web pages from the rest of the computer, preventing malicious sites from accessing your files or system settings. If exploited, an attacker who has already gained control of a browser tab could potentially break out of that isolation to perform unauthorized actions on the underlying Windows operating system.
Technical details
An improper input validation vulnerability (CWE-20) exists in the Media component of Google Chrome on Windows. The flaw allows a remote attacker who has already achieved code execution within the sandboxed renderer process to perform a sandbox escape. By enticing a user to visit a specially crafted HTML page, the attacker can leverage the insufficient validation to interact with higher-privilege browser or OS processes. This vulnerability is addressed in Google Chrome version 150.0.7871.47 for Windows.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched