Executive brief
Google Chrome is a widely used web browser. A security vulnerability in the browser's Receiver component could allow a remote attacker to bypass security boundaries. If an attacker has already compromised a website's rendering process, they could use this flaw to escape the browser's 'sandbox,' potentially gaining unauthorized access to the underlying operating system or user data.
Technical details
This vulnerability is classified as a policy bypass within the Receiver component of the Chromium engine. The flaw allows an attacker who has already achieved code execution within a sandboxed renderer process to bypass security policies. By enticing a user to visit a specially crafted HTML page, the attacker can leverage this bypass to perform a sandbox escape. This escalation allows the attacker to move from the restricted renderer process to the more privileged browser process or the host operating system. The issue was addressed in Google Chrome version 151.0.7922.72.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Stable channel update released for Windows, Mac, and Linux.
- 2026-07-30: disclosed: CVE published to NVD.