Description
Insufficient validation of untrusted input in Settings in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Published: 2026-06-30
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Insufficient validation of untrusted input in Chrome Settings on Windows allows a remote attacker who has already compromised the renderer process to perform a sandbox escape. The flaw stems from improper input handling (CWE‑20) and can lift the attacker’s privileges beyond the isolated renderer, potentially giving control of the Chrome process and the host operating system.

Affected Systems

Google Chrome for Windows users running a Chromium release older than 150.0.7871.47 are affected. The vulnerability targets the renderer sandbox and does not appear to require disabling other security features.

Risk and Exploitability

The CVSS score of 8.3 indicates a high severity sandbox escape, while the EPSS score of less than 1% suggests that exploitation is very unlikely under current conditions. The CVE description implies that an attacker must first compromise the renderer process before exploiting the sandbox escape; this is inferred from the wording "remote attacker who had compromised the renderer process". The vulnerability is not listed in CISA’s KEV catalog, indicating no widespread exploitation has been reported.

Generated by OpenCVE AI on July 31, 2026 at 16:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 150.0.7871.47 or later, which includes the input‑validation fix.
  • Enable automatic updates to ensure that future security patches are applied automatically.
  • Use Chrome’s default security settings or install an extension that blocks untrusted content to reduce exposure to malicious renderer pages.

Generated by OpenCVE AI on July 31, 2026 at 16:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Fri, 31 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title Chrome Windows Settings Input Validation Leads to Sandbox Escape

Sun, 26 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title Chrome Windows Settings Input Validation Leads to Sandbox Escape

Tue, 21 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Title Insufficient Validation in Chrome Settings Allows Sandbox Escape

Thu, 16 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Insufficient Validation in Chrome Settings Allows Sandbox Escape

Tue, 14 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Chrome Sandbox Escape via Untrusted Input in Settings on Windows

Mon, 13 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Title Chrome Sandbox Escape via Untrusted Input in Settings on Windows

Sun, 12 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Unchecked Input in Chrome Settings Enables Renderer Sandbox Escape

Sat, 11 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Unchecked Input in Chrome Settings Enables Renderer Sandbox Escape

Thu, 09 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Insufficient input validation in Chrome Settings enabling potential sandbox escape on Windows

Tue, 07 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Title Insufficient input validation in Chrome Settings enabling potential sandbox escape on Windows

Mon, 06 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Untrusted Input in Chrome Settings Enables Potential Sandbox Escape

Sun, 05 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title Untrusted Input in Chrome Settings Enables Potential Sandbox Escape

Sun, 05 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Chrome Settings Input Validation Weakness Allows Sandbox Escape on Windows

Sat, 04 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Chrome Settings Input Validation Weakness Allows Sandbox Escape on Windows

Sat, 04 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Insufficient Validation in Chrome Settings Allows Sandbox Escape on Windows

Sat, 04 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Title Insufficient Validation in Chrome Settings Allows Sandbox Escape on Windows

Fri, 03 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Title Chrome Settings Input Validation Flaw Enables Sandbox Escape

Fri, 03 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Title Chrome Settings Input Validation Flaw Enables Sandbox Escape

Thu, 02 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Chrome Settings Input Validation Leading to Sandbox Escape on Windows

Thu, 02 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Title Chrome Settings Input Validation Leading to Sandbox Escape on Windows

Wed, 01 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Chrome Settings Input Validation Leading to Sandbox Escape

Wed, 01 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title Chrome Settings Input Validation Leading to Sandbox Escape

Wed, 01 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Insufficient Validation of Untrusted Input in Settings Leads to Sandbox Escape in Chrome on Windows

Wed, 01 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Title Insufficient Validation of Untrusted Input in Settings Leads to Sandbox Escape in Chrome on Windows

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Insufficient validation of untrusted input in Settings in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-02T03:56:31.659Z

Reserved: 2026-06-29T23:03:27.952Z

Link: CVE-2026-13829

cve-icon Vulnrichment

Updated: 2026-07-01T15:03:41.228Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T16:30:17Z

Weaknesses
  • CWE-20

    Improper Input Validation