Executive brief
A vulnerability in Google Chrome's GPU component could allow a remote attacker to bypass security boundaries. If an attacker has already compromised the browser's rendering process, they could use this flaw to escape the 'sandbox'—a security layer designed to prevent malicious websites from accessing the rest of the computer. This could lead to unauthorized access to the user's local system and data.
Technical details
An insufficient policy enforcement vulnerability exists in the GPU component of Google Chrome prior to version 150.0.7871.47. The flaw allows a remote attacker to perform a sandbox escape via a specially crafted HTML page, provided they have already achieved code execution within a compromised renderer process. By exploiting this lack of enforcement, the attacker can move from the restricted renderer environment to the more privileged GPU process. This vulnerability is classified by Chromium as Low severity. Users should update to version 150.0.7871.47 or later to mitigate this risk.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched