Executive brief
Google Chrome is a widely used web browser. A vulnerability in the printing component on Windows could allow a remote attacker who has already compromised a browser tab to break out of the security sandbox. This could lead to unauthorized access to the underlying operating system and user data.
Technical details
An improper input validation vulnerability (CWE-20) exists in the Printing component of Google Chrome for Windows. The flaw allows a remote attacker to perform a sandbox escape, provided they have already achieved code execution within a compromised renderer process. The attack is typically delivered via a specially crafted HTML page. This vulnerability was addressed in version 151.0.7922.72. Google classifies the severity of this specific issue as Low.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in version 151.0.7922.72
- 2026-07-30: disclosed