Executive brief
Google Chrome is a widely used web browser. A security flaw in its Human Interface Device (HID) component could allow a malicious website to execute unauthorized code on a user's computer. This could lead to the theft of sensitive information or full control over the affected system if a user visits a specially crafted webpage.
Technical details
An insufficient policy enforcement vulnerability exists in the Human Interface Device (HID) implementation of Google Chrome. The flaw allows a remote attacker to potentially execute arbitrary code by enticing a user to visit a maliciously crafted HTML page. The root cause is a failure to strictly enforce security policies within the HID interface, which manages communication with peripheral devices. While the Chromium team has rated this as 'Low' severity, the impact of successful exploitation could include remote code execution. The issue is resolved in Google Chrome version 150.0.7871.47 and later.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: advisory: NVD publication date
- 2026-06-30: patched: Stable channel update released