Executive brief
Google Chrome's Tracing component contains an incorrect reference resolution vulnerability that allows a local attacker to execute arbitrary code outside the browser's sandbox by exploiting a flaw through a local program. This could give an attacker full system-level control, bypassing Chrome's security isolation and potentially compromising the entire device.
Technical details
The vulnerability is an incorrect reference resolution flaw in the Tracing component of Google Chrome on Windows. A local attacker with limited privileges can exploit this issue through a local program to achieve arbitrary code execution outside the Chrome sandbox. The vulnerability allows an attacker to escape the browser's security isolation, gaining the ability to execute code with system privileges. The fix was released in Chrome version 153.0.8010.52 and later versions for Windows and Mac, and 153.0.8010.52 for Linux. This is classified as a sandbox escape vulnerability with High severity by the Chromium security team.
Affected products
- Google Chrome prior to 153.0.8010.52
Timeline
- 2026-09-17: disclosed
- 2026-09-17: patched