CVE-2026-18002
9.6Google · Chrome
A vulnerability in Google Lens within Chrome allows a remote attacker to achieve a sandbox escape after compromising the renderer process via a crafted HTML page.
Executive summary
A critical sandbox escape vulnerability in Google Chrome allows remote attackers to bypass browser security boundaries, posing a severe risk to system integrity.
Vulnerability
The flaw stems from insufficient validation of untrusted input within the Google Lens component. An unauthenticated attacker who has already compromised the renderer process can execute a sandbox escape by luring a user to visit a specially crafted HTML page.
Business impact
Successful exploitation of this vulnerability permits an attacker to escape the browser sandbox, potentially leading to full system compromise, data theft, or malware installation on the host machine. Given the CVSS score of 9.6, this represents a critical risk that could result in significant reputational damage and widespread loss of control over endpoint assets.
Remediation
Immediate Action: Update all instances of Google Chrome to version 151.0.7922.72 or later immediately to incorporate the necessary security patches.
Proactive Monitoring: Review endpoint security logs for anomalous process behavior or unexpected crashes in the Chrome renderer process, which may indicate attempted exploitation.
Compensating Controls: Ensure that all browser instances are running with the latest security updates, and consider utilizing endpoint detection and response (EDR) solutions to monitor for unauthorized system-level calls originating from the browser process.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
This vulnerability is classified as critical due to its potential for total system compromise following a sandbox escape. Organizations must prioritize the deployment of the latest Chrome update across all workstations to mitigate the risk of remote code execution. Failure to patch this flaw leaves systems exposed to advanced exploitation chains that can bypass standard browser-level protections.