Executive brief
Google Chrome is a web browser used by billions of people to access websites and online services. A flaw in the browser's editing functionality allowed attackers to bypass authorization checks and view sensitive information by sending users a specially crafted web page, potentially exposing private data without requiring any special user permissions.
Technical details
This vulnerability is an incorrect authorization flaw in the Editing component of Google Chrome. An unauthenticated remote attacker can exploit this by crafting a malicious HTML page that, when loaded in a vulnerable version of Chrome, bypasses authorization controls to access sensitive information. The vulnerability affects Chrome versions prior to 152.0.7977.65 on Windows, Mac, and Linux. Google released Chrome 152.0.7977.65 (and 152.0.7977.64 on Linux) as the fixed version addressing this and 326 other security issues.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Chrome 152.0.7977.65 released