Description
Insufficient validation of untrusted input in Settings in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Published: 2026-06-30
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Insufficient validation of untrusted input in Chrome Settings on Windows allows a remote attacker who has already compromised the renderer process to perform a sandbox escape. The flaw results from improper input handling (CWE-20) and lets the attacker gain higher privileges than those granted to the isolated renderer, potentially allowing control of the Chrome process and the host operating system.

Affected Systems

Google Chrome for Windows users running a Chromium release older than 150.0.7871.47 are affected. The vulnerability targets the renderer sandbox and does not rely on additional security features being disabled.

Risk and Exploitability

The CVSS score of 8.3 indicates a high severity for a sandbox escape, while the EPSS score of less than 1% implies that exploitation is very rare. Based on the description, it is inferred that an attacker must first compromise the renderer process before exploiting the sandbox escape, which reduces the immediate threat for users who have not been targeted yet. The vulnerability is not listed in CISA's KEV catalog, suggesting no widespread attacks have been observed.

Generated by OpenCVE AI on July 21, 2026 at 17:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 150.0.7871.47 or later, which contains the fix for the input validation issue.
  • Ensure that the browser is kept up to date so that future security patches are applied promptly.
  • Consider using Chrome's default security settings or an extension that blocks untrusted content to limit exposure to malicious renderer pages.

Generated by OpenCVE AI on July 21, 2026 at 17:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Tue, 21 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Title Insufficient Validation in Chrome Settings Allows Sandbox Escape

Thu, 16 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Insufficient Validation in Chrome Settings Allows Sandbox Escape

Tue, 14 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Chrome Sandbox Escape via Untrusted Input in Settings on Windows

Mon, 13 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Title Chrome Sandbox Escape via Untrusted Input in Settings on Windows

Sun, 12 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Unchecked Input in Chrome Settings Enables Renderer Sandbox Escape

Sat, 11 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Unchecked Input in Chrome Settings Enables Renderer Sandbox Escape

Thu, 09 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Insufficient input validation in Chrome Settings enabling potential sandbox escape on Windows

Tue, 07 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Title Insufficient input validation in Chrome Settings enabling potential sandbox escape on Windows

Mon, 06 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Untrusted Input in Chrome Settings Enables Potential Sandbox Escape

Sun, 05 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title Untrusted Input in Chrome Settings Enables Potential Sandbox Escape

Sun, 05 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Chrome Settings Input Validation Weakness Allows Sandbox Escape on Windows

Sat, 04 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Chrome Settings Input Validation Weakness Allows Sandbox Escape on Windows

Sat, 04 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Insufficient Validation in Chrome Settings Allows Sandbox Escape on Windows

Sat, 04 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Title Insufficient Validation in Chrome Settings Allows Sandbox Escape on Windows

Fri, 03 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Title Chrome Settings Input Validation Flaw Enables Sandbox Escape

Fri, 03 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Title Chrome Settings Input Validation Flaw Enables Sandbox Escape

Thu, 02 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Chrome Settings Input Validation Leading to Sandbox Escape on Windows

Thu, 02 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Title Chrome Settings Input Validation Leading to Sandbox Escape on Windows

Wed, 01 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Chrome Settings Input Validation Leading to Sandbox Escape

Wed, 01 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title Chrome Settings Input Validation Leading to Sandbox Escape

Wed, 01 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Insufficient Validation of Untrusted Input in Settings Leads to Sandbox Escape in Chrome on Windows

Wed, 01 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Title Insufficient Validation of Untrusted Input in Settings Leads to Sandbox Escape in Chrome on Windows

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Insufficient validation of untrusted input in Settings in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-02T03:56:31.659Z

Reserved: 2026-06-29T23:03:27.952Z

Link: CVE-2026-13829

cve-icon Vulnrichment

Updated: 2026-07-01T15:03:41.228Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T17:30:09Z

Weaknesses
  • CWE-20

    Improper Input Validation