Executive brief
Google Chrome is a widely used web browser. A vulnerability in the browser's Content Settings allowed a remote attacker to bypass security restrictions that normally control how websites can access certain features or data. By tricking a user into visiting a specially crafted webpage, an attacker could potentially perform actions or access information that should have been restricted by the browser's security policies.
Technical details
A vulnerability classified as insufficient policy enforcement exists in the Content Settings component of Google Chrome. The flaw allows a remote attacker to bypass discretionary access control (DAC) mechanisms. To exploit this, an attacker must entice a user to visit a maliciously crafted HTML page. Successful exploitation could allow the attacker to circumvent security policies intended to restrict site permissions or content behavior. The issue is addressed in Chrome version 149.0.7827.53.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
- 2026-06-05: disclosed: NVD publication date.