Executive brief
Google Chrome contains a missing authorization vulnerability in its extension handling mechanism that affects versions prior to 153.0.8010.36. A remote attacker can exploit this flaw by crafting a malicious Chrome extension to obtain sensitive information from the browser. This could allow unauthorized access to user data, browsing history, credentials, or other private information stored within Chrome.
Technical details
The vulnerability is a missing authorization check in Chrome's extension system (CWE-862: Missing Authorization). An attacker can create a crafted Chrome extension that bypasses authorization controls to access sensitive information that should be restricted. The attack vector is network-based and requires the user to install or interact with the malicious extension. The vulnerability affects Chrome versions prior to 153.0.8010.36, and Google has published a fix in the stable release of Chrome 153.0.8010.36 for Windows, Mac, and Linux platforms.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched: Fixed in Chrome 153.0.8010.36