Description
Insufficient validation of untrusted input in Linux Toolkit Theming in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Published: 2026-07-14
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Insufficient validation of untrusted input in the Linux Toolkit Theming component of Google Chrome allows an attacker who has already compromised the renderer process to escape the sandbox and execute arbitrary code with system privileges. This flaw is a CWE-20 input validation weakness and a CWE-807 resource path traversal vulnerability that can lead to full compromise of the affected machine if successfully exploited.

Affected Systems

The vulnerability impacts Google Chrome users on Linux where the browser version is older than 150.0.7871.125. Any installation of Chrome on a Linux distribution that has not applied the latest update is susceptible.

Risk and Exploitability

The CVSS score of 8.3 classifies the flaw as high, but the EPSS score of less than 1% suggests that current exploitation attempts are rare or unlikely. The flaw is not listed in CISA’s KEV catalog, indicating no widespread use of publicly available exploits at this time. The likely attack vector is the delivery of a crafted HTML page that the compromised renderer processes, after which an attacker could gain privileges beyond the sandbox.

Generated by OpenCVE AI on August 3, 2026 at 03:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome on Linux to version 150.0.7871.125 or newer via the official update channel
  • Enable automatic security updates in Chrome so future patches are applied promptly
  • Consider restricting or disabling the loading of untrusted content in the browser by configuring appropriate security policies

Generated by OpenCVE AI on August 3, 2026 at 03:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4687-1 chromium security update
Debian DSA Debian DSA DSA-6390-1 chromium security update
History

Wed, 29 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title Sandbox Escape via Untrusted Input in Chrome Linux Toolkit Theming chromium-browser: chromium-browser: Insufficient validation of untrusted input in Linux Toolkit Theming
Weaknesses CWE-807
References
Metrics threat_severity

None

threat_severity

Important


Sun, 26 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Sandbox Escape via Untrusted Input in Chrome Linux Toolkit Theming

Wed, 22 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Title Sandbox Escape via Insufficient Input Validation in Chrome Linux Toolkit Theming

Thu, 16 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Sandbox Escape via Insufficient Input Validation in Chrome Linux Toolkit Theming

Wed, 15 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 14 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description Insufficient validation of untrusted input in Linux Toolkit Theming in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-14T20:44:10.471Z

Reserved: 2026-07-14T18:31:15.640Z

Link: CVE-2026-15769

cve-icon Vulnrichment

Updated: 2026-07-14T20:44:07.950Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Important

Publid Date: 2026-07-14T20:09:52Z

Links: CVE-2026-15769 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T03:15:05Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-807

    Reliance on Untrusted Inputs in a Security Decision