Executive brief
A security vulnerability has been identified in Google Chrome's Enterprise component, which manages corporate-level browser policies and features. An attacker could exploit this flaw by tricking a user into visiting a specially crafted website, potentially allowing the attacker to gain elevated permissions on the user's system. This could lead to unauthorized access to sensitive data or the ability to bypass security restrictions within a managed corporate environment.
Technical details
An improper input validation vulnerability (CWE-20) exists in the Enterprise component of Google Chrome prior to version 150.0.7871.47. The flaw is triggered when the browser processes untrusted input from a specially crafted HTML page. A remote, unauthenticated attacker can exploit this to perform privilege escalation within the browser's context. The vulnerability was assigned a Medium severity rating by the Chromium project. Users are advised to update to version 150.0.7871.47 or later to mitigate this risk.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched