
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-12468 is a race condition vulnerability in the Updater component of Google Chrome on macOS that allows a remote attacker who has already compromised the renderer process to perform a sandbox escape via a crafted HTML page. It affects all Google Chrome versions prior to 149.0.7827.155 on Mac. The vulnerability was reported to Google on June 8, 2026, and patched on June 16, 2026, as part of a 33-fix stable channel update. It carries a CVSS v3.1 base score of 8.3 (High) (Chrome Releases, Red Hat Bugzilla).
The root cause is a race condition (CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization; CWE-368: Context Switching Race Condition) in Chrome's Updater component on macOS. An attacker who has already achieved renderer process compromise can exploit the timing window during Updater operations — consistent with CAPEC-26 (Leveraging Race Conditions) and CAPEC-29 (TOCTOU Race Conditions) — to escape the Chrome sandbox by delivering a crafted HTML page. Exploitation requires user interaction (visiting a malicious page) and a pre-compromised renderer, making it a second-stage exploitation primitive rather than a standalone initial access vector (Chrome Releases, Red Hat Bugzilla).
Successful exploitation allows an attacker with a compromised Chrome renderer process to escape the browser sandbox on macOS, potentially enabling arbitrary code execution outside the sandboxed environment with high impact to confidentiality, integrity, and availability. This could allow the attacker to access sensitive data on the host system, install persistent malware, or pivot to other resources accessible from the compromised machine. The scope is marked as "Changed" in the CVSS assessment, reflecting that the impact extends beyond the sandboxed browser process to the underlying operating system (Chrome Releases).
GoogleSoftwareUpdate or Chrome Updater processes, including unexpected privilege escalation events or sandbox policy violations.Google has released a patch in Chrome version 149.0.7827.155 (Linux) and 149.0.7827.155/.156 (Windows/Mac), which addresses this vulnerability along with 32 other security fixes. Users and administrators should update Google Chrome to version 149.0.7827.155 or later immediately. As a temporary workaround where patching is not immediately possible, organizations can restrict execution of untrusted web content, implement application whitelisting, and consider disabling or restricting Chrome's auto-update mechanism in managed environments while deploying the patch through alternative means (Chrome Releases).
Security news outlets including CyberSecurityNews and CyberNoz covered the broader June 2026 Chrome update, highlighting the batch of 33 security fixes including 7 Critical-severity issues alongside this High-severity sandbox escape. Coverage noted the significance of the update given the volume and severity of fixes. The vulnerability was also tracked by downstream distributors including Red Hat, openSUSE, Fedora, FreeBSD, and Debian, all of which issued Chromium package updates in the days following Google's release (CyberSecurityNews, Chrome Releases).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."