Executive brief
A vulnerability in the Safe Browsing component of Google Chrome for Mac could allow a remote attacker to execute unauthorized code on a user's system. Safe Browsing is a security feature designed to protect users from malicious websites and files; an exploit in this component could lead to a full system compromise if a user interacts with a malicious file. Users should update to the latest version of Chrome to mitigate this risk.
Technical details
An inappropriate implementation vulnerability exists in the Safe Browsing component of Google Chrome for macOS. The flaw allows a remote attacker to achieve arbitrary code execution by enticing a user to interact with or download a specifically crafted malicious file. While the Chromium project classifies the severity as 'Low,' the potential impact includes the execution of untrusted code within the context of the browser or underlying system. The issue is addressed in Chrome version 149.0.7827.53 and later.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released for Mac
- 2026-06-04: disclosed: CVE published to NVD