Executive brief
A vulnerability in Google Chrome's developer tools (DevTools) could allow a malicious browser extension to access data from other websites. To exploit this, an attacker would first need to trick a user into installing a specifically crafted malicious extension. This could lead to the unauthorized exposure of sensitive information from different web services the user is currently accessing.
Technical details
A vulnerability classified as insufficient policy enforcement exists within the DevTools component of Google Chrome. The flaw allows a malicious Chrome Extension to bypass cross-origin restrictions and leak data from other origins. Exploitation requires the attacker to successfully induce a user to install a specially crafted extension. Once installed, the extension leverages the DevTools interface to access information it should not have permission to view. This issue was addressed in Google Chrome version 149.0.7827.53.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
- 2026-06-04: disclosed: CVE published to NVD