Description
Insufficient data validation in Storage in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-06-30
Score: 5.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Insufficient data validation in Chrome’s Storage component allows a remote process to craft an HTML page that may trigger a sandbox escape. The flaw is identified as CWE‑122, indicating a buffer or bounds‑check oversight. Although the description does not confirm arbitrary code execution, the privilege escalation from within the renderer sandbox remains a concern.

Affected Systems

All installations of Google Chrome running a version older than 150.0.7871.47 are affected, regardless of operating system. The vulnerability is present in the storage code that processes HTML in the renderer.

Risk and Exploitability

The CVSS score of 5.8 indicates a moderate severity, while the EPSS score of less than 1% signals a very low likelihood of exploitation in the wild. This vulnerability is not listed in the CISA KEV catalog, and no public exploits are known. The attack requires the attacker to first compromise the renderer process, typically by serving malicious web content, after which the poor data validation in the Storage component could enable a sandbox escape.

Generated by OpenCVE AI on July 16, 2026 at 12:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 150.0.7871.47 or later, or enable the browser’s automatic update mechanism to receive the fix.
  • If an upgrade cannot be performed immediately, limit exposure by restricting or blocking untrusted web content and configure policies that isolate renderer processes.
  • Apply a strict content‑security policy to reduce the chance that malicious scripts can reach the renderer.

Generated by OpenCVE AI on July 16, 2026 at 12:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Thu, 16 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Insufficient Data Validation in Chrome Storage Enabling Potential Sandbox Escape

Tue, 14 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Chrome Storage Buffer Validation Flaw May Enable Renderer Sandbox Escape

Mon, 13 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Title Chrome Storage Buffer Validation Flaw May Enable Renderer Sandbox Escape

Sun, 12 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Insufficient Data Validation in Chrome Storage Enables Potential Sandbox Escape

Sat, 11 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Insufficient Data Validation in Chrome Storage Enables Potential Sandbox Escape

Fri, 10 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Title Chrome Storage Data Validation Failure Enabling Sandbox Escape

Thu, 09 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Chrome Storage Data Validation Failure Enabling Sandbox Escape

Wed, 08 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in Chrome Storage Allows Potential Sandbox Escape

Wed, 08 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in Chrome Storage Allows Potential Sandbox Escape

Tue, 07 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title Insufficient Data Validation in Chrome Storage Allows Potential Sandbox Escape

Mon, 06 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Title Insufficient Data Validation in Chrome Storage Allows Potential Sandbox Escape

Mon, 06 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Title Insufficient Data Validation in Storage Allows Sandbox Escape with Compromised Renderer

Sun, 05 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Insufficient Data Validation in Storage Allows Sandbox Escape with Compromised Renderer

Sun, 05 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Chrome Storage Validation Flaw Could Allow Sandbox Escape After Renderer Compromise

Sat, 04 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Chrome Storage Validation Flaw Could Allow Sandbox Escape After Renderer Compromise

Sat, 04 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
Title Insufficient Data Validation Enables Potential Sandbox Escape in Chrome Storage

Fri, 03 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title Insufficient Data Validation Enables Potential Sandbox Escape in Chrome Storage

Thu, 02 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Google Chrome Storage Component Sandbox Escape Vulnerability

Thu, 02 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Google Chrome Storage Component Sandbox Escape Vulnerability

Thu, 02 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title Sandbox Escape via Insufficient Storage Validation in Chrome

Wed, 01 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Sandbox Escape via Insufficient Storage Validation in Chrome

Wed, 01 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 08:00:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in Chrome Storage Allows Sandbox Escape

Wed, 01 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in Chrome Storage Allows Sandbox Escape

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Insufficient data validation in Storage in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-122
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T19:31:49.643Z

Reserved: 2026-06-29T23:04:06.315Z

Link: CVE-2026-13976

cve-icon Vulnrichment

Updated: 2026-07-01T19:31:45.689Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-16T12:30:03Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow