Junglewise Threat Intelligence

CVE-2026-18015: Google Chrome Tint sandbox escape on macOS

CVE-2026-18015 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability exists in Google Chrome for Mac within the Tint component, which handles shader programs. A remote attacker could use a specially crafted website to potentially bypass the browser's security sandbox. If successful, this could allow the attacker to gain unauthorized access to the underlying operating system, though the severity is currently rated as low.

Technical details

An inappropriate implementation vulnerability exists in the Tint component of Google Chrome for macOS. Tint is the compiler for the WebGPU Shading Language (WGSL). By enticing a user to visit a malicious website containing a crafted HTML page, a remote attacker could trigger this flaw to achieve a sandbox escape. The vulnerability is present in versions prior to 151.0.7922.72. Google has addressed this issue in the stable channel update for desktop.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in version 151.0.7922.72
  • 2026-07-30: disclosed

References

Related threats