Executive brief
Google Chrome is a widely-used web browser that includes Bluetooth connectivity features on macOS systems. A vulnerability in the Bluetooth component allows attackers who have already compromised the browser's renderer process to trick users through social engineering into disclosing sensitive information via specially crafted web pages. While this requires multiple attack preconditions, it could expose personal or confidential data stored in the browser.
Technical details
This is an information leak vulnerability in the Bluetooth subsystem of Google Chrome on macOS. The vulnerability requires an attacker to have already compromised the renderer process (e.g., through a prior sandbox escape or separate exploit), and then leverage social engineering to craft a malicious HTML page that triggers the leak. When a user visits the crafted page, sensitive information can be exposed through the Bluetooth component. The issue affects Chrome versions prior to 152.0.7977.65 on macOS. Google addressed this in the Chrome 152 stable release published on August 25, 2026.
Affected products
- Google Chrome prior to 152.0.7977.65 on macOS
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched