Executive brief
Google Chrome contains a security flaw in its browser extension system that could allow a malicious extension to access data from other websites. To exploit this, an attacker must first trick a user into installing a specifically crafted malicious extension. If successful, the attacker could bypass standard security boundaries to view or modify information on sites the user visits.
Technical details
An inappropriate implementation in the Extensions component of Google Chrome allowed for a Same Origin Policy (SOP) bypass. The vulnerability stems from insufficient validation of untrusted input within the extension framework. An attacker who successfully convinces a user to install a crafted malicious extension can exploit this flaw to access data across different origins. This issue is resolved in Google Chrome version 149.0.7827.155 and later. While the vendor rates the severity as High, the CVSS score provided by CISA-ADP is 4.2 (Medium) due to the requirement for user interaction and high attack complexity.
Affected products
- Google Chrome prior to 149.0.7827.155
Timeline
- 2026-05-27: other: Reported to Google
- 2026-06-16: patched: Stable channel update released
- 2026-06-17: advisory: NVD publication date