Executive brief
A security vulnerability exists in the Color component of Google Chrome on ChromeOS. This flaw could allow a malicious website to break out of the browser's security sandbox if the browser's rendering process has already been compromised. Successfully exploiting this could give an attacker deeper access to the underlying operating system, potentially leading to unauthorized data access or full system control.
Technical details
This vulnerability is classified as a heap-based buffer overflow (CWE-122) within the Color component of Google Chrome on ChromeOS. The flaw is reachable via a crafted HTML page. A precondition for this exploit is a prior compromise of the renderer process. If achieved, a remote attacker can leverage this overflow to bypass the browser sandbox and execute code in the context of the operating system. Google has addressed this issue in ChromeOS version 151.0.7922.72.
Affected products
- Google ChromeOS prior to 151.0.7922.72
Timeline
- 2026-05-25: disclosed: Reported to Chromium project
- 2026-07-29: patched: Fixed in stable channel update 151.0.7922.72
- 2026-07-30: advisory: NVD publication date