Executive brief
Google Chrome is a widely used web browser. A vulnerability in its Serial API component could allow a malicious website to gain unauthorized privileges on a user's system. This could potentially lead to unauthorized access to hardware or sensitive data if a user visits a specially crafted webpage.
Technical details
A privilege escalation vulnerability exists in the Serial API component of Google Chrome due to insufficient policy enforcement. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page. The flaw allows the attacker to bypass intended security restrictions and escalate privileges within the browser context. Google has addressed this issue in version 150.0.7871.47 and later.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched
- 2026-06-30: advisory