Executive brief
Google Chrome's browser contained incomplete cleanup of extension-related state, allowing a malicious extension to bypass the web origin policy that normally prevents one website from accessing data or functionality belonging to another. An attacker could exploit this through social engineering to trick a user into installing a crafted extension, potentially exposing sensitive cross-site data or enabling unauthorized actions on behalf of the user.
Technical details
This vulnerability is a same-origin policy (SOP) bypass in Google Chrome's browser engine. The root cause is incomplete cleanup of state in the Browser component when handling Chrome extensions, allowing a crafted malicious extension to escape the intended sandboxing restrictions. An attacker must first socially engineer a user into installing the malicious extension, after which the incomplete cleanup enables the extension to bypass web origin policy protections and access cross-origin data or functionality. The vulnerability was patched in Chrome 153.0.8010.36 and later versions.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched: Fixed in Chrome 153.0.8010.36