Executive brief
Google Chrome contains a missing authorization vulnerability in its InterestGroups feature that allows a remote attacker with control of the renderer process to bypass system access restrictions via a crafted PDF file. This could enable an attacker to access or modify protected browsing features without proper authorization, potentially affecting user privacy and security.
Technical details
The vulnerability is a missing authorization flaw in the InterestGroups component of Google Chrome prior to version 152.0.7977.65. The attack requires an attacker to have already compromised the renderer process, and leverages a crafted PDF file to trigger the authorization bypass. The vulnerability allows bypassing system access restrictions within the renderer context. This is a post-compromise attack that extends renderer privileges through missing authorization checks. The vulnerability was patched in Chrome 152.0.7977.65.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Chrome 152.0.7977.65