Executive brief
Google Chrome, a widely used web browser, contained a security vulnerability in its internal communication system. If an attacker already managed to compromise a website's rendering process, they could potentially bypass the browser's security sandbox. This could allow the attacker to gain broader access to the underlying operating system or user data beyond the restricted browser environment.
Technical details
A vulnerability exists in the Mojo IPC (Inter-Process Communication) framework of Google Chrome due to insufficient policy enforcement. The flaw allows a remote attacker who has already achieved code execution within a compromised renderer process to escalate privileges. By utilizing a specially crafted HTML page, the attacker can potentially bypass sandbox restrictions and interact with more privileged browser processes. This issue is resolved in Google Chrome version 150.0.7871.47 and later.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: advisory: NVD and Chrome Release blog published advisory
- 2026-06-30: patched: Fixed in version 150.0.7871.47