Executive brief
Google Chrome, a widely used web browser, contained a vulnerability in its Extensions component. This flaw could allow a remote attacker who has already compromised a browser tab to break out of the security sandbox. If successful, an attacker could potentially gain broader access to the underlying operating system or user data beyond the browser's restricted environment.
Technical details
An improper input validation vulnerability (CWE-20) exists in the Extensions component of Google Chrome. The flaw allows a remote attacker who has already achieved code execution within a compromised renderer process to bypass sandbox restrictions. By utilizing a specially crafted HTML page, the attacker can exploit insufficient validation of untrusted input to escape the renderer sandbox. This vulnerability is addressed in Google Chrome version 151.0.7922.72 for Windows, Mac, and Linux.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in version 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date