Executive brief
A security vulnerability in Google Chrome for macOS could allow an attacker to bypass the browser's security sandbox. Chrome uses a sandbox to isolate web pages from the rest of the computer, preventing malicious sites from accessing personal files or system settings. If exploited, an attacker who has already gained some control over the browser's rendering process could use a specially crafted web page to break out of this isolation and potentially gain broader access to the user's Mac.
Technical details
A sandbox escape vulnerability exists in the MHTML implementation of Google Chrome for macOS. The flaw is categorized as an 'inappropriate implementation' within the MHTML component. To exploit this, a remote attacker must first compromise the renderer process (typically via a separate vulnerability). Once the renderer is compromised, the attacker can use a specially crafted HTML page to bypass sandbox restrictions. This could lead to unauthorized access to the underlying operating system. The issue is resolved in Chrome version 151.0.7922.72 for Mac.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-06-04: other: Reported to Google
- 2026-07-29: patched: Stable channel update released
- 2026-07-30: disclosed: CVE published