Executive brief
Google Chrome, a widely used web browser, contains a vulnerability in its import functionality that allows attackers to bypass security sandboxing. A remote attacker could trick a user into opening a malicious file, potentially gaining the ability to execute arbitrary code with elevated privileges outside Chrome's normal security boundaries, leading to complete system compromise.
Technical details
This vulnerability is a privilege elevation flaw in Chrome's Import component that permits sandbox escape. The attack requires social engineering to convince a user to open a crafted file via the import mechanism. By exploiting this flaw, an attacker can execute arbitrary code outside the sandboxed browser environment, achieving full code execution at the user's privilege level. The vulnerability was patched in Chrome version 151.0.7922.173 and later, released on August 20, 2026.
Affected products
- Google Chrome prior to 151.0.7922.173
Timeline
- 2026-08-20: disclosed: Published in Chrome 151.0.7922.173 stable release
- 2026-08-20: patched: Fixed in Chrome 151.0.7922.173 and later