Executive brief
Google Chrome is a widely used web browser. A vulnerability in the browser's download component allowed remote attackers to bypass security restrictions that normally prevent unauthorized file downloads. This could be used to trick users into downloading potentially harmful files via a specially crafted website.
Technical details
An improper input validation vulnerability (CWE-20) exists in the Downloads component of Google Chrome for Windows. The flaw stems from insufficient validation of untrusted input, which allows a remote attacker to bypass established download restrictions. To exploit this, an attacker must entice a user to visit a specially crafted HTML page. Successful exploitation could allow the attacker to trigger downloads that would otherwise be blocked by browser security policies. The issue is resolved in version 147.0.7727.55.
Affected products
- Google Chrome prior to 147.0.7727.55
Timeline
- 2026-02-20: disclosed: Reported by daffainfo
- 2026-04-07: patched: Stable channel update released
- 2026-04-08: advisory: NVD publication date