Executive brief
A vulnerability exists in Google Chrome's QUIC networking component, which is used for fast data transfer. An attacker who has already compromised a browser's rendering process could use this flaw to escape the security sandbox. This could allow the attacker to gain broader access to the underlying operating system and user data.
Technical details
An integer overflow vulnerability exists in the QUIC protocol implementation within Google Chrome. The flaw is located in the networking stack and can be triggered by a remote attacker who has already achieved code execution within a compromised renderer process. By leveraging a specially crafted HTML page, the attacker can exploit this overflow to bypass the Chromium sandbox. This leads to a sandbox escape, potentially allowing for full system compromise. The issue is addressed in Chrome version 151.0.7922.72.
Affected products
- Google Chrome Prior to 151.0.7922.72
Timeline
- 2026-05-16: disclosed: Reported to Google
- 2026-07-29: patched: Fixed in Stable Channel Update 151.0.7922.72
- 2026-07-30: advisory: NVD publication date