Executive brief
A vulnerability in Google Chrome's password management component could allow a malicious website to break out of the browser's security sandbox. This occurs if an attacker has already partially compromised the browser's rendering process, potentially allowing them to gain broader access to the underlying operating system. Users should update to the latest version of Chrome to mitigate this risk.
Technical details
Google Chrome prior to 151.0.7922.72 is vulnerable to a sandbox escape due to insufficient validation of untrusted input within the Passwords component. An attacker who has already achieved code execution within a compromised renderer process can leverage a specially crafted HTML page to bypass sandbox restrictions. This vulnerability is classified by Chromium as Medium severity. Users are advised to update to version 151.0.7922.72 or later on Windows, Mac, and Linux.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: advisory: Google released the stable channel update fixing the issue.
- 2026-07-30: disclosed: NVD published the CVE record.