Executive brief
A vulnerability in the Google Chrome web browser on Windows could allow a local user to gain elevated system privileges. By using a specially crafted malicious file, an attacker who already has basic access to the computer could bypass security boundaries within the browser's user interface. This could lead to unauthorized access to sensitive data or the ability to perform administrative actions on the affected device.
Technical details
An inappropriate implementation and insufficient validation of untrusted input in the UI component of Google Chrome on Windows allowed for local privilege escalation. The vulnerability (CWE-20) is triggered when the browser processes a malicious file, allowing an attacker with local access to bypass security restrictions. This issue was identified by Google internally and is addressed in version 149.0.7827.53. While the NVD entry lists the severity as 'info', the Chromium project classifies this as a 'High' severity security flaw.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-04-18: disclosed: Reported internally by Google
- 2026-06-02: patched: Fixed in stable channel update 149.0.7827.53/54
- 2026-06-04: advisory: CVE published to NVD