Executive brief
A security vulnerability exists in Google Chrome for macOS within the component responsible for installing web applications. If an attacker has already partially compromised the browser's internal processes, they could use a specially crafted webpage to break out of the security 'sandbox' that normally isolates the browser from the rest of the computer. This could allow the attacker to gain broader access to the underlying operating system.
Technical details
This vulnerability is classified as an inappropriate implementation within the WebAppInstalls component of Google Chrome for macOS. The flaw allows a remote attacker to achieve a sandbox escape, provided they have already achieved code execution within a compromised renderer process. The attack is triggered via a specifically crafted HTML page. By escaping the sandbox, the attacker can move from the restricted browser environment to the broader host operating system. The issue is addressed in Chrome version 150.0.7871.47.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: advisory
- 2026-06-30: patched