Executive brief
Google Chrome is a widely used web browser deployed on billions of devices. A vulnerability in the Chrome Tabs component allows a remote attacker to bypass system access restrictions by opening a specially crafted HTML page, potentially enabling unauthorized access to restricted resources without user or system verification.
Technical details
The vulnerability is an injection flaw in the Chrome Tabs component of Google Chrome prior to version 152.0.7977.65. The root cause involves insufficient input validation or filtering of untrusted data within the tabs rendering or navigation logic. An attacker can deliver a malicious HTML page via network (e.g., via web link or email) that, when opened in the browser, injects code or manipulates tab state to bypass access control checks. No user interaction beyond opening the HTML page is required. A successful exploit permits an attacker to circumvent system-level access restrictions that would normally enforce security boundaries. The vulnerability was patched in Chrome 152.0.7977.65 and later versions.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65