Executive brief
A vulnerability in Google Chrome's developer tools (DevTools) could allow a malicious browser extension to gain elevated privileges on a user's system. To exploit this, an attacker must first trick a user into installing a specifically crafted malicious extension. If successful, the attacker could bypass security boundaries to access sensitive data or perform unauthorized actions within the browser environment.
Technical details
A privilege escalation vulnerability exists in Google Chrome's DevTools component due to insufficient policy enforcement. The flaw allows a crafted Chrome Extension to bypass intended security restrictions and escalate its privileges within the browser context. Exploitation requires a user to install a malicious extension, typically through social engineering. Once installed, the extension can leverage the DevTools interface to execute actions with higher authority than normally permitted for extensions. This issue is resolved in Google Chrome version 149.0.7827.53 and later.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
- 2026-06-04: disclosed: CVE-2026-11092 published.