Protection Mechanism Failure in OpenClaw - CVE-2026-32046
Published: May 1, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote attacker to weaken browser isolation.
The vulnerability exists due to protection mechanism failure in the sandbox browser container when launching Chromium with the --no-sandbox option enabled by default. A remote attacker can exploit a renderer-side bug to weaken browser isolation.
Exploitation removes the need for a separate sandbox escape after renderer compromise.