Executive brief
Google Chrome contains a missing authorization vulnerability in its BrowserTag component that allows a remote attacker to obtain sensitive information through a malicious Chrome extension, but only if a user is socially engineered into installing it. This could expose user data or enable further attacks against vulnerable users.
Technical details
This is a missing authorization vulnerability in Google Chrome's BrowserTag component affecting versions prior to 152.0.7977.65. The vulnerability allows a remote attacker to bypass authorization checks and access sensitive information via a crafted Chrome extension. The attack vector requires social engineering to trick a user into installing the malicious extension, meaning direct network exploitation is not possible. An attacker who successfully delivers the extension gains the ability to read sensitive data accessible to the browser. The issue is patched in Chrome 152.0.7977.65 and later releases.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65