Executive brief
Google Chrome's Safe Browsing feature, which protects users from malicious websites and downloads, contains a vulnerability that could allow a remote attacker to bypass security controls. By using a specially crafted file, an attacker can circumvent discretionary access controls intended to restrict unauthorized actions. This could lead to the execution of unauthorized files or the bypass of security warnings designed to protect user data.
Technical details
A vulnerability exists in the Safe Browsing component of Google Chrome due to improper input validation (CWE-20). The flaw allows a remote attacker to bypass discretionary access control (DAC) mechanisms by providing a malicious file that is not correctly validated by the Safe Browsing engine. This bypass could potentially allow for unauthorized file operations or the circumvention of security policies intended to block malicious content. The issue is addressed in Chrome version 151.0.7922.72 for Windows, Mac, and Linux.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in version 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date