Executive brief
Google Chrome's address bar (Omnibox) contains a missing authorization vulnerability that allows an attacker to trick users into bypassing browser security restrictions and accessing privileged pages through a crafted HTML page. An attacker could potentially gain unauthorized access to sensitive browser features or user data through social engineering.
Technical details
This vulnerability is a missing authorization check in the Omnibox (Chrome's address bar and search component). The flaw allows a remote attacker to craft a malicious HTML page that, through social engineering tactics, can bypass system access restrictions and gain entry to privileged pages without proper authorization checks. The attack requires user interaction (clicking or visiting the malicious page). The vulnerability was patched in Chrome 153.0.8010.36 released on September 8, 2026.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched: Fixed in Chrome 153.0.8010.36