Executive brief
A security vulnerability exists in Google Chrome for macOS that could allow a malicious website to bypass the browser's security sandbox. If an attacker has already compromised the part of the browser that displays web pages, they could use this flaw to gain broader access to the underlying operating system. This could lead to unauthorized access to local files, data theft, or the installation of malicious software.
Technical details
A race condition (CWE-362) exists within the Downloads component of Google Chrome for macOS. The vulnerability allows a remote attacker who has already achieved code execution within a compromised renderer process to escape the Chrome sandbox. By enticing a user to visit a specially crafted HTML page, the attacker can exploit this synchronization issue to gain elevated privileges on the host operating system. The issue is addressed in Chrome version 151.0.7922.72 for Mac.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-06-04: disclosed: Reported to Chromium project
- 2026-07-29: patched: Fixed in Stable Channel Update 151.0.7922.72
- 2026-07-30: advisory: NVD publication date