Executive brief
Google Chrome for Mac is a popular web browser used to access the internet and web-based applications. A security vulnerability in the browser's cryptography component could allow a malicious website to break out of the browser's security sandbox. If successful, an attacker who has already gained control of a browser tab could potentially access the underlying operating system and user data on the Mac.
Technical details
A vulnerability classified as an 'inappropriate implementation' exists within the Crypto component of Google Chrome for macOS. The flaw allows a remote attacker who has already achieved code execution within a compromised renderer process to bypass sandbox restrictions. By enticing a user to visit a specially crafted HTML page, the attacker can leverage this implementation flaw to escape the browser sandbox and execute commands with the privileges of the browser process. This issue was addressed in Chrome version 151.0.7922.72 for Mac.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in Stable Channel Update 151.0.7922.72 for Mac
- 2026-07-30: disclosed: NVD publication date