Executive brief
A vulnerability in Google Chrome for Linux could allow a malicious browser extension to read sensitive information from the browser's memory. To exploit this, an attacker would need to trick a user into installing a specifically crafted extension. This could lead to the exposure of private data handled by the browser process.
Technical details
An out-of-bounds read vulnerability exists in the Extensions component of Google Chrome for Linux prior to version 149.0.7827.53. The flaw is triggered when a user installs a malicious, crafted Chrome Extension. This allows the extension to bypass intended memory boundaries and read potentially sensitive information from the browser's process memory. The vulnerability is classified as a heap-based buffer overflow (CWE-122) and was addressed in the stable channel update for version 149.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released for Linux
- 2026-06-04: disclosed: CVE published