Executive brief
Google Chrome's printing component failed to properly validate user input, allowing an attacker who had already compromised the browser's rendering process to execute arbitrary code outside Chrome's security sandbox. This could lead to complete system compromise if an attacker combines this vulnerability with other exploits to first break into the browser.
Technical details
The vulnerability is an improper input validation flaw in Chrome's Printing component affecting versions prior to 152.0.7977.65. The attack requires that an attacker has already compromised the renderer process, which normally runs in a sandbox to isolate untrusted content. By crafting a malicious HTML page, the attacker can exploit the validation weakness to escape the sandbox and execute arbitrary code with elevated privileges on the host system. This is a sandbox escape vulnerability. The fix is available in Chrome 152.0.7977.65 and later.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65