Executive brief
A security vulnerability exists in Google Chrome for macOS that could allow a malicious website to break out of the browser's security sandbox. This occurs due to a timing issue in how the browser handles file downloads. If exploited, an attacker who has already gained limited control over a browser tab could potentially gain broader access to the underlying operating system, compromising user data and system integrity.
Technical details
A race condition (CWE-362) exists in the Downloads component of Google Chrome for macOS. The vulnerability allows a remote attacker who has already achieved code execution within a compromised renderer process to escalate privileges and escape the Chrome sandbox. This is achieved by exploiting improper synchronization during download operations via a specially crafted HTML page. The issue is resolved in Google Chrome version 151.0.7922.72 for Mac.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-06-04: disclosed: Reported to Google internally
- 2026-07-29: patched: Fixed in stable channel update 151.0.7922.72
- 2026-07-30: advisory: NVD publication date