Executive brief
A vulnerability in Google Chrome's Bluetooth component could allow a remote attacker to bypass security protections. If an attacker has already compromised a website's rendering process, they could use a specially crafted web page to escape the browser's security sandbox. This could potentially allow the attacker to gain broader access to the underlying operating system.
Technical details
An improper input validation vulnerability (CWE-20) exists in the Bluetooth component of Google Chrome. The flaw allows a remote attacker who has already achieved code execution within a compromised renderer process to bypass sandbox restrictions. By leveraging a crafted HTML page, the attacker can exploit insufficient validation of untrusted input to perform a sandbox escape. This vulnerability is addressed in Google Chrome version 151.0.7922.72.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in Chrome Stable Channel Update 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date