Description
Inappropriate implementation in AI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-06-30
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw stems from an inappropriate implementation in Google Chrome’s artificial‑intelligence component that existed in releases before version 150.0.7871.47. A remote attacker who has already compromised the renderer process can serve a specially crafted HTML page to the victim's browser. The malicious page may trigger the AI component to escape the browser’s sandbox, elevating the renderer process to a higher privilege level. If this happens the attacker could execute arbitrary code on the host system, compromising confidentiality, integrity, and availability of the machine.

Affected Systems

All installations of Google Chrome that are older than 150.0.7871.47 on any supported operating system are affected. Users who have not upgraded remain at risk until the update is installed.

Risk and Exploitability

The CVSS score of 8.3 indicates a high severity. The EPSS score of less than 1 % suggests that exploitation is currently unlikely, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires a two‑step attack: first the renderer process must be subverted, then a malicious HTML page must be delivered to trigger the AI component flaw. Successful exploitation would lift the renderer process into a higher‑privilege context, enabling arbitrary code execution. The weakness is categorized as CWE‑693.

Generated by OpenCVE AI on July 15, 2026 at 22:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 150.0.7871.47 or newer to patch the AI component and eliminate the sandbox escape flaw.
  • Ensure that automatic updates are enabled or manually apply security updates to Chrome promptly.
  • Maintain least‑privilege for processes; run Chrome in isolated user accounts and limit network access to reduce the impact of a potential escape.

Generated by OpenCVE AI on July 15, 2026 at 22:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Wed, 15 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title Sandbox Escape via AI Component in Google Chrome Before 150.0.7871.47

Tue, 14 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Sandbox Escape via AI Component in Google Chrome Before 150.0.7871.47

Sat, 11 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
Title Sandbox Escape via Crafted HTML in Google Chrome AI Component

Fri, 10 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Title Sandbox Escape via Crafted HTML in Google Chrome AI Component

Thu, 09 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title AI Component Vulnerability Enables Sandbox Escape in Google Chrome

Wed, 08 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title AI Component Vulnerability Enables Sandbox Escape in Google Chrome

Wed, 08 Jul 2026 08:00:00 +0000

Type Values Removed Values Added
Title Sandbox Escape Vulnerability in Google Chrome AI Component

Tue, 07 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title Sandbox Escape Vulnerability in Google Chrome AI Component

Mon, 06 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Remote Renderer Process Compromise Enables Sandbox Escape in Chrome AI Component

Sun, 05 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Remote Renderer Process Compromise Enables Sandbox Escape in Chrome AI Component

Sun, 05 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Title Chrome Sandbox Escape via AI Component in Versions Prior to 150.0.7871.47

Sat, 04 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Chrome Sandbox Escape via AI Component in Versions Prior to 150.0.7871.47

Fri, 03 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Sandbox Escape via AI-Driven Renderer Vulnerability in Google Chrome

Fri, 03 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Sandbox Escape via AI-Driven Renderer Vulnerability in Google Chrome

Thu, 02 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Title AI Implementation Vulnerability Allows Sandbox Escape in Chrome

Thu, 02 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title AI Implementation Vulnerability Allows Sandbox Escape in Chrome

Thu, 02 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Title AI Implementation Flaw Enabling Sandbox Escape in Chrome

Wed, 01 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Title AI Implementation Flaw Enabling Sandbox Escape in Chrome
Weaknesses CWE-264
CWE-305

Wed, 01 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Title Inappropriate AI Implementation Allows Sandbox Escape in Google Chrome

Wed, 01 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-693
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Wed, 01 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Inappropriate AI Implementation Allows Sandbox Escape in Google Chrome
Weaknesses CWE-264
CWE-305

Wed, 01 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Sandbox Escape via Malicious HTML in Chrome
Weaknesses CWE-264
CWE-305

Wed, 01 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title Sandbox Escape via Malicious HTML in Chrome
Weaknesses CWE-264
CWE-305

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in AI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T15:20:59.850Z

Reserved: 2026-06-29T23:11:52.079Z

Link: CVE-2026-14151

cve-icon Vulnrichment

Updated: 2026-07-01T12:49:55.185Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-15T23:00:17Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure