Executive brief
Google Chrome's permission system failed to properly validate extension access requests, allowing malicious extensions to bypass authorization checks. A remote attacker could use social engineering to trick users into installing a crafted extension that obtains sensitive information without proper user consent, compromising user privacy and data security.
Technical details
This vulnerability is an incorrect authorization flaw in Chrome's permissions system affecting versions prior to 153.0.8010.36. The vulnerability allows an attacker to bypass permission validation through a crafted Chrome extension, leveraging social engineering to trick users into installation. The attack is network-based and requires user interaction (installing the malicious extension). An attacker can exploit this to access sensitive information that should be protected by the permissions model. The vulnerability was fixed in Chrome 153.0.8010.36, released on September 8, 2026.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched: Chrome 153.0.8010.36 released