Executive brief
A security vulnerability exists in the Enterprise component of Google Chrome, a web browser used for accessing internal and external web applications. An attacker with a privileged position on the network could bypass security controls intended to restrict access to specific resources. This could allow unauthorized access to sensitive data or internal systems that should otherwise be protected by the browser's access policies.
Technical details
A cryptographic flaw exists in the Enterprise component of Google Chrome prior to version 151.0.7922.72. The vulnerability allows an attacker in a privileged network position (such as a Man-in-the-Middle) to bypass discretionary access control (DAC) mechanisms by injecting or manipulating malicious network traffic. This flaw stems from an inappropriate implementation of cryptographic protections within enterprise-specific features. Successful exploitation could lead to the bypass of administrative security policies. The issue was resolved in the Stable channel update to version 151.0.7922.72.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-05-10: disclosed: Reported by Google internal researchers
- 2026-07-29: patched: Fixed in Chrome Stable channel update 151.0.7922.72
- 2026-07-30: advisory: NVD publication date