Executive brief
A race condition vulnerability exists in the DevTools component of Google Chrome for macOS. This flaw could allow a remote attacker who has already compromised a browser tab to break out of the security sandbox. If successful, the attacker could gain unauthorized access to the underlying operating system, potentially leading to data theft or full system compromise.
Technical details
A race condition (CWE-362) exists in the DevTools component of Google Chrome for macOS. The vulnerability allows a remote attacker who has already achieved code execution within a compromised renderer process to escalate privileges and escape the browser sandbox. This is achieved by exploiting improper synchronization during concurrent execution, triggered via a specially crafted HTML page. The issue is specific to the Mac platform and was addressed in Chrome version 151.0.7922.72. Google classifies this as a Medium severity issue within their internal ranking, though sandbox escapes typically represent a significant security boundary violation.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in Stable Channel Update 151.0.7922.72 for Mac
- 2026-07-30: disclosed: NVD publication date