Executive brief
A vulnerability exists in Google Chrome's DevTools, a set of web developer tools built directly into the browser. An attacker who has already partially compromised the browser's rendering process could use this flaw to escape the security sandbox. If successful, this could allow the attacker to gain broader access to the underlying operating system and the user's private data.
Technical details
An improper input validation vulnerability (CWE-20) exists in the DevTools component of Google Chrome. The flaw allows a remote attacker who has already achieved code execution within a compromised renderer process to bypass sandbox restrictions. By enticing a user to visit a specially crafted HTML page, the attacker can exploit the insufficient validation of untrusted input to escalate privileges and escape the browser sandbox. This issue is addressed in Google Chrome version 151.0.7922.72.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched
- 2026-07-30: disclosed