Executive brief
Google Chrome's USB subsystem incorrectly validates authorization for accessing USB devices, allowing a remote attacker to bypass system access restrictions through social engineering. An attacker could craft a malicious webpage that tricks a user into granting unauthorized USB device access, potentially exposing sensitive data or enabling control of connected USB hardware.
Technical details
This is an incorrect authorization vulnerability in Chrome's USB handling subsystem. The vulnerability allows a remote attacker to bypass system access restrictions via a crafted HTML page when the user is socially engineered into interacting with it. The attack vector is network-based and requires user interaction (social engineering). An attacker can achieve unauthorized access to USB devices that should be restricted. The vulnerability was patched in Chrome version 152.0.7977.65 and later.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65