Executive brief
A vulnerability in the Enterprise component of Google Chrome could allow a person with physical access to a device to gain higher-level system permissions. This could potentially allow an unauthorized user to bypass certain security restrictions or access data they should not have permission to see. The issue is specific to the Enterprise management features of the browser and requires the attacker to be physically present at the machine.
Technical details
An inappropriate implementation vulnerability exists in the Enterprise component of Google Chrome. The flaw allows a local attacker with physical access to the target device to perform privilege escalation. The root cause is an implementation error within the Enterprise management logic, though specific code-level details are restricted. The vulnerability is mitigated by the requirement for physical access and is classified by Chromium as Low severity. Users should update to version 149.0.7827.53 or later to remediate the issue.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
- 2026-06-04: disclosed: CVE published to NVD