Executive brief
Google Chrome is a widely used web browser. A security vulnerability was identified in the way the browser handles extensions, which could allow a remote attacker who has already partially compromised the browser's rendering process to gain higher levels of access. This could potentially lead to unauthorized actions or access to sensitive data within the browser environment.
Technical details
This vulnerability is classified as an improper input validation (CWE-20) issue within the Extensions component of Google Chrome. The flaw exists because the browser does not sufficiently validate untrusted input, allowing a remote attacker to escalate privileges. To exploit this, an attacker must first compromise the renderer process and then utilize a specially crafted HTML page. The vulnerability was addressed in Google Chrome version 150.0.7871.47. Chromium developers have assigned this a 'Medium' severity rating.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: advisory: NVD publication date
- 2026-06-30: patched: Stable channel update released