Executive brief
A vulnerability in the Google Chrome browser for macOS could allow a malicious website to escape the browser's security sandbox. This occurs if an attacker first compromises the browser's rendering process, typically by tricking a user into visiting a specially crafted webpage. If successful, the attacker could gain broader access to the underlying operating system, potentially leading to data theft or unauthorized software installation.
Technical details
An improper input validation vulnerability (CWE-20) exists in the Updater component of Google Chrome for macOS. The flaw allows a remote attacker who has already compromised the renderer process to bypass sandbox restrictions via a crafted HTML page. By exploiting this lack of validation, the attacker can transition from the restricted renderer environment to the broader system context. The vulnerability is addressed in Google Chrome version 151.0.7922.72 for Mac.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: advisory: Google released the stable channel update fixing the issue.
- 2026-07-30: disclosed: CVE published in the NVD.