Executive brief
Google Chrome is a widely used web browser. A security flaw in its Bluetooth component could allow a malicious website to gain unauthorized permissions or elevate its privileges on a user's system. This could potentially lead to unauthorized access to device features if a user visits a specially crafted webpage.
Technical details
A privilege escalation vulnerability exists in the Bluetooth component of Google Chrome due to insufficient policy enforcement. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page. If successful, the attacker could bypass intended security restrictions to gain elevated privileges within the browser context. The vulnerability is addressed in Chrome version 150.0.7871.47 and later.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched