Executive brief
Google Chrome is a widely used web browser that supports third-party extensions to add functionality. A security flaw in the way Chrome handles extension policies could allow a malicious extension to bypass security restrictions. If a user is tricked into installing a specially crafted extension, the attacker could gain unauthorized access to data or perform actions on websites that should have been restricted.
Technical details
A vulnerability exists in the Extensions component of Google Chrome due to insufficient policy enforcement. The flaw allows a malicious extension to bypass discretionary access control (DAC) mechanisms by utilizing a specially crafted domain name. To exploit this, an attacker must first convince a user to install a malicious extension. Once installed, the extension can circumvent intended security boundaries to access restricted resources or data. This issue is addressed in Chrome version 151.0.7922.72.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in version 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date