Race in DevTools in Google Chrome prior to 126.0.6478.182 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted Chrome Extension. (Chromium security severity: High)
https://github.com/yaghoubkhani/chrome_sandbox_scape_CVE-2024-5836_CVE-2024-6778
https://github.com/ading2210/CVE-2024-6778-POC
https://issues.chromium.org/issues/341136300
https://chromereleases.googleblog.com/2024/07/stable-channel-update-for-desktop.html