Executive brief
Google Chrome for Linux is affected by a security vulnerability in its file input handling. A remote attacker could use a specially crafted website to bypass the browser's security sandbox, which is designed to keep malicious code from affecting the rest of the computer. If successful, this could allow an attacker to gain unauthorized access to the underlying operating system and user data.
Technical details
A sandbox escape vulnerability exists in the File Input component of Google Chrome for Linux. The flaw stems from an inappropriate implementation that fails to properly isolate file input operations, allowing a remote attacker to break out of the Chromium renderer sandbox. An attacker can exploit this by enticing a user to visit a maliciously crafted HTML page. Successful exploitation could lead to arbitrary code execution on the host operating system with the privileges of the user running the browser. The issue is resolved in version 151.0.7922.72.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in version 151.0.7922.72 for Linux
- 2026-07-30: disclosed: NVD publication date