Executive brief
Google Chrome is a widely used web browser. A vulnerability in the Device Trust component on Windows could allow a remote attacker who has already partially compromised the browser to escape its security sandbox. If successful, this could allow the attacker to gain broader access to the underlying Windows operating system, potentially leading to unauthorized data access or system control.
Technical details
An improper input validation vulnerability (CWE-20) exists in the Device Trust component of Google Chrome for Windows. The flaw allows a remote attacker to perform a sandbox escape if they have already achieved code execution within the renderer process (e.g., via a separate exploit). By enticing a user to visit a specially crafted HTML page, the attacker can leverage the insufficient validation to break out of the browser's restricted environment. This issue was fixed in version 150.0.7871.47. Google characterizes the severity of this specific sandbox escape vector as Low.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched