Description
Integer overflow in Mojo in Google Chrome prior to 149.0.7827.201 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)
Published: 2026-06-25
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An integer overflow (CWE-472) was discovered in the Mojo inter‑process communication system used by Google Chrome. The flaw allows a remote attacker who already has control of the renderer process to perform a sandbox escape, potentially executing code with elevated privileges. The vulnerability is classified as high severity by Chromium security.

Affected Systems

The flaw affects Google Chrome on desktop platforms in any version prior to 149.0.7827.201. All earlier releases are vulnerable until updated to the patched build.

Risk and Exploitability

The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, which limits public information on exploitation prevalence. Chromium's own assessment marks it as high severity, indicating that exploitation could lead to complete compromise of the system hosting the browser. The attack requires the attacker to have already compromised the renderer process, so a prior foothold is necessary. The lack of a publicly documented exploit coupled with the high severity suggests a moderate to high risk for systems that remain on affected versions.

Generated by OpenCVE AI on June 25, 2026 at 23:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 149.0.7827.201 or later.
  • Ensure the browser’s auto‑update feature is enabled or apply the update manually to stay current with security patches.
  • Monitor renderer process activity for anomalous behavior and take corrective action if suspicious patterns are detected.

Generated by OpenCVE AI on June 25, 2026 at 23:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 26 Jun 2026 00:15:00 +0000

Type Values Removed Values Added
Title Integer Overflow in Chrome's Mojo Enables Potential Sandbox Escape

Thu, 25 Jun 2026 22:00:00 +0000

Type Values Removed Values Added
Description Integer overflow in Mojo in Google Chrome prior to 149.0.7827.201 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)
Weaknesses CWE-472
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-06-25T21:51:33.035Z

Reserved: 2026-06-24T21:53:13.178Z

Link: CVE-2026-13281

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-26T00:00:14Z

Weaknesses
  • CWE-472

    External Control of Assumed-Immutable Web Parameter