Executive brief
Google Chrome for macOS is a popular web browser used for accessing the internet and running web applications. A security flaw in the browser's sandbox—a protective layer designed to isolate web pages from the rest of the computer—could allow a malicious website to gain unauthorized access to the underlying system. If exploited, an attacker who has already compromised a web page's rendering process could bypass security restrictions to access files or execute commands on the user's Mac.
Technical details
An insufficient policy enforcement vulnerability exists in the Sandbox component of Google Chrome for macOS. The flaw allows a remote attacker who has already achieved code execution within a compromised renderer process to bypass sandbox restrictions. By enticing a user to visit a specially crafted HTML page, the attacker can escalate privileges to escape the sandbox environment. This issue affects Google Chrome on Mac prior to version 150.0.7871.47. The vulnerability is mitigated by the requirement of a prior renderer compromise, leading to its 'Low' severity rating by Chromium.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: advisory
- 2026-06-30: disclosed
- 2026-06-30: patched