Executive brief
A security vulnerability in Google Chrome for macOS could allow a malicious website to bypass the browser's security sandbox. This sandbox is designed to keep web content isolated from the rest of the computer; if bypassed, an attacker who has already compromised the browser's rendering process could potentially gain broader access to the underlying operating system. Users should update to the latest version of Chrome to mitigate this risk.
Technical details
An improper input validation vulnerability (CWE-20) exists in the UI component of Google Chrome on macOS. The flaw allows a remote attacker who has already achieved code execution within a compromised renderer process to escape the Chrome sandbox. By utilizing a specially crafted HTML page, the attacker can exploit insufficient validation of untrusted input to interact with the browser's UI layer in a way that grants elevated privileges or access to the host system. This issue is resolved in Chrome version 148.0.7778.216 and later.
Affected products
- Google Chrome prior to 148.0.7778.216
Timeline
- 2026-05-01: other: Reported by Google internal researchers
- 2026-05-27: patched: Stable channel update released
- 2026-05-28: disclosed: CVE published