Junglewise Threat Intelligence

CVE-2026-10997: Google Chrome insufficient policy enforcement in Extensions

CVE-2026-10997 · Severity: info · CVSS 4.3 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's extension system could allow a malicious extension to bypass security restrictions. If a user is tricked into installing a specially crafted extension, the attacker could gain unauthorized access to data or perform actions that should normally be restricted by the browser's security policies. This could lead to the exposure of sensitive user information or unauthorized changes to browser settings.

Technical details

An insufficient policy enforcement vulnerability exists in the Extensions component of Google Chrome. The flaw allows a crafted Chrome Extension to bypass discretionary access control (DAC) mechanisms. To exploit this, an attacker must successfully trick a user into installing a malicious extension. Once installed, the extension can circumvent intended security boundaries to access data or functionality it should not have permission to reach. This issue is resolved in Google Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
  • 2026-06-04: disclosed: CVE published and NVD record created

References

Related threats