top of page
perceptive_background_267k.jpg

Inappropriate implementation in Tint in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a craf…

Published:

29 July 2026 at 22:00:00

Alert date:

30 July 2026 at 17:11:53

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Zero-Day Vulnerabilities, Operating Systems

CVE-2026-18015 describes an inappropriate implementation in the Tint component of Google Chrome on macOS. The vulnerability affects versions prior to 151.0.7922.72 and allows a remote attacker to potentially perform a sandbox escape. The attack vector involves a specially crafted HTML page, meaning exploitation can be triggered via the browser without additional user interaction beyond visiting a malicious page. Chromium has rated the severity of this vulnerability as Low. The fix was included in the stable channel desktop update released in July 2026. Despite the low Chromium severity rating, sandbox escapes are inherently serious as they can allow attackers to break out of browser isolation. Users on macOS running affected Chrome versions should update immediately to the patched release.

Technical details

Mitigation steps:

Affected products:

Google Chrome on macOS prior to 151.0.7922.72

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page