Executive brief
Google Chrome is a widely used web browser that includes support for third-party extensions to add custom functionality. An authorization flaw in the Extensions system allows remote attackers to bypass system access restrictions through a specially crafted malicious extension, requiring social engineering to trick users into installing it. Successful exploitation could allow attackers to circumvent security controls and gain unauthorized access to system resources.
Technical details
The vulnerability is an incorrect authorization issue in Google Chrome's Extensions system, affecting versions prior to 152.0.7977.65. The flaw allows a remote attacker to bypass system access restrictions through a crafted Chrome extension; this requires social engineering to trick a user into installing the malicious extension. The attack vector is network-based with user interaction required. An attacker can leverage this to circumvent security boundaries enforced by the extension sandbox and access restricted system resources. The vulnerability is patched in Chrome 152.0.7977.65 and later versions.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65