Executive brief
A vulnerability in the Views component of Google Chrome on ChromeOS could allow a malicious extension to access sensitive information. To exploit this, an attacker must trick a user into installing a specially crafted Chrome extension. Once installed, the extension could read data from the browser's process memory, potentially exposing private user information.
Technical details
An inappropriate implementation in the Views component of Google Chrome on ChromeOS allowed for information disclosure. The vulnerability is triggered when a user installs and executes a malicious, specially crafted Chrome Extension. An attacker can leverage this flaw to read sensitive information from the browser's process memory. This issue was addressed in ChromeOS version 150.0.7871.47. The vulnerability is classified by Chromium as Low severity.
Affected products
- Google ChromeOS prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched