Executive brief
A vulnerability in Google Chrome's extension system could allow a malicious extension to bypass security restrictions that normally control how the browser navigates between pages. To exploit this, an attacker would need to trick a user into installing a specifically crafted malicious extension. This could lead to unauthorized navigation or the bypassing of intended security boundaries within the browser.
Technical details
An inappropriate implementation vulnerability exists in the Extensions component of Google Chrome prior to version 149.0.7827.53. The flaw allows a crafted Chrome Extension to bypass navigation restrictions that are intended to govern how the browser transitions between different web contexts or origins. Exploitation requires a user to be socially engineered into installing a malicious extension. Once installed, the extension can programmatically trigger navigations that should otherwise be restricted by the browser's security model. Google has addressed this issue in the stable channel update for desktop.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Fixed in version 149.0.7827.53
- 2026-06-04: disclosed: NVD publication date