Executive brief
Google Chrome's Tint graphics rendering component on macOS contains an improper validation flaw that could allow an attacker to execute malicious code outside Chrome's security sandbox through a crafted webpage. This bypasses Chrome's primary defense mechanism and could lead to complete system compromise, including theft of data and installation of malware.
Technical details
The vulnerability is an improper quantity validation issue in the Tint component of Google Chrome on macOS prior to version 153.0.8010.36. The flaw allows a remote attacker to bypass the Chrome sandbox and achieve arbitrary code execution outside the sandboxed environment via a specially crafted HTML page. No user interaction beyond visiting a malicious webpage is required. The vulnerability was patched in Chrome 153.0.8010.36/.37 released on September 8, 2026, and was assigned Chromium security severity of Medium despite the critical impact of sandbox escape.
Affected products
- Google Chrome prior to 153.0.8010.36/.37 on macOS
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched: Chrome 153.0.8010.36/.37 released for Windows/Mac/Linux