Executive brief
A security bypass exists in Google Chrome's Safe Browsing feature, which is designed to protect users from malicious websites and downloads. By using a specially crafted RAR archive file, an attacker could potentially bypass security checks that are intended to restrict access to certain files or content. This could lead to the delivery of malicious content that would otherwise be blocked by the browser's built-in security controls.
Technical details
A vulnerability classified as an inappropriate implementation exists in the Safe Browsing component of Google Chrome. The flaw allows a remote attacker to bypass discretionary access control (DAC) mechanisms by delivering a specifically crafted RAR archive. This bypass occurs because the Safe Browsing engine fails to correctly process or inspect the contents of the crafted archive, potentially allowing malicious files to evade detection or security restrictions. The vulnerability is reachable over the network and requires minimal user interaction (e.g., downloading the file). The issue is resolved in Google Chrome version 149.0.7827.53 and later.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome stable channel update released version 149.0.7827.53
- 2026-06-04: disclosed: CVE published to NVD