Executive brief
A vulnerability in Google Chrome's extension system allowed malicious browser extensions to bypass security controls. If a user is tricked into installing a specially crafted extension, the attacker could gain unauthorized access to data or perform actions that should normally be restricted. This could lead to the exposure of sensitive user information or unauthorized changes to browser settings.
Technical details
An inappropriate implementation in the Extensions component of Google Chrome prior to version 149.0.7827.53 allowed a crafted extension to bypass discretionary access control (DAC). The vulnerability requires a user to be socially engineered into installing a malicious extension. Once installed, the extension can leverage this flaw to access resources or perform operations that are typically restricted by the browser's permission model. Google has addressed this issue in the stable channel update for desktop.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
- 2026-06-04: disclosed: CVE-2026-11190 published