Executive brief
A vulnerability in Google Chrome for macOS could allow a remote attacker to bypass security protections. By convincing a user to visit a specially crafted website, an attacker who has already gained limited control over the browser's content rendering process could escape the 'sandbox'—a security layer designed to isolate the browser from the rest of the computer. This could potentially lead to unauthorized access to the underlying operating system and user data.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in the Media component of Google Chrome on macOS. The flaw can be triggered by a remote attacker who has already compromised the renderer process, typically via a malicious HTML page. By exploiting this memory safety issue, the attacker may be able to achieve a sandbox escape, gaining elevated privileges on the host system. The vulnerability is addressed in Google Chrome version 151.0.7922.72 for Mac.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in version 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date