Executive brief
Google Chrome contains an authorization flaw in its SiteSettings feature that allows attackers to bypass system access restrictions by hosting a specially crafted webpage. An attacker could use this vulnerability to access restricted site capabilities or bypass security policies that administrators or users have configured to protect system resources.
Technical details
An incorrect authorization check exists in the SiteSettings component of Google Chrome versions prior to 152.0.7977.75. The vulnerability allows a remote attacker to bypass system access restrictions by crafting a malicious HTML page that exploits the flawed authorization logic. The attack requires the user to visit the attacker's crafted webpage, but no other authentication or privileges are required. An attacker can exploit this to gain unauthorized access to restricted site capabilities or circumvent security policies configured by the user or system administrator.
Affected products
- Google Chrome prior to 152.0.7977.75
Timeline
- 2026-09-02: disclosed
- 2026-09-02: patched: Fixed in Chrome 152.0.7977.75