Junglewise Threat Intelligence

CVE-2026-13951: Google Chrome sandbox escape in USB component

CVE-2026-13951 · Severity: info · CVSS 6.5 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability in Google Chrome's USB component could allow a malicious website to bypass security boundaries. If a user visits a specially crafted webpage, an attacker who has already partially compromised the browser's internal processes could escape the 'sandbox'—a security layer designed to keep web content isolated from the rest of the computer. This could lead to unauthorized access to the underlying system or user data.

Technical details

A sandbox escape vulnerability exists in the USB component of Google Chrome due to insufficient policy enforcement. The flaw allows a remote attacker to bypass security restrictions if they have already achieved code execution within the renderer process (typically via a separate vulnerability). By enticing a user to visit a malicious HTML page, the attacker can leverage this weakness to escape the Chromium sandbox. This issue affects Google Chrome versions prior to 150.0.7871.47. Users are advised to update to the latest stable channel release to mitigate this risk.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched
  • 2026-06-30: advisory

References

Related threats