Executive brief
A vulnerability in Google Chrome's developer tools could allow a malicious browser extension to access sensitive information stored in the computer's memory. To exploit this, an attacker would first need to trick a user into installing a specifically crafted malicious extension. This could lead to the exposure of private data from other open tabs or browser processes.
Technical details
An insufficient policy enforcement vulnerability exists within the DevTools component of Google Chrome. The flaw allows a malicious Chrome Extension to bypass intended security boundaries and read sensitive information from process memory. Exploitation requires a user to be socially engineered into installing a malicious extension. Once installed, the extension can leverage DevTools interfaces to access memory contents that should be restricted. Google has addressed this issue in version 150.0.7871.47 and later.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched