Executive brief
Google Chrome is a widely used web browser for accessing the internet and internal applications. A security flaw in the browser's Feedback component could allow a remote attacker to bypass the browser's security sandbox. If exploited, this could allow an attacker to gain unauthorized access to the underlying operating system, potentially leading to data theft or the installation of malicious software.
Technical details
An improper input validation vulnerability (CWE-20) exists in the Feedback component of Google Chrome. The flaw allows a remote attacker who has already compromised the renderer process to escape the browser's sandbox environment by utilizing a specially crafted HTML page. This vulnerability requires user interaction (visiting a malicious site) and is characterized by a high complexity attack vector. Successful exploitation grants the attacker the ability to execute code outside of the restricted browser environment on the host operating system. The issue is resolved in Google Chrome version 147.0.7727.138 and later.
Affected products
- Google Chrome prior to 147.0.7727.138
Timeline
- 2026-04-28: disclosed: Initial publication by Google Chrome team
- 2026-04-28: patched: Fixed in version 147.0.7727.138