Executive brief
A vulnerability in Google Chrome's 'Save to Drive' feature could allow a remote attacker to bypass security protections. If an attacker has already compromised a browser tab, they could use a specially crafted PDF file to escape the browser's security sandbox. This could lead to unauthorized access to the underlying operating system and the user's local data.
Technical details
An improper input validation vulnerability (CWE-20) exists in the 'Save to Drive' component of Google Chrome. The flaw allows a remote attacker who has already achieved code execution within a compromised renderer process to escalate privileges and perform a sandbox escape. The attack is triggered by processing a specially crafted PDF file through the Save to Drive workflow. This vulnerability is mitigated by the requirement of a prior renderer compromise. Google has addressed this issue in Chrome version 151.0.7922.72 for Windows, Mac, and Linux.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in version 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date