Executive brief
Google Chrome's Loader component contains an authorization flaw that allows an attacker to craft a malicious HTML page to bypass security controls. An attacker can trick a user into visiting the page to extract sensitive information from the browser, potentially exposing personal or account data without requiring special privileges.
Technical details
This vulnerability is an incorrect authorization issue in Chrome's Loader component that allows bypass of access controls. An attacker can craft a specially designed HTML page to trigger the flaw; the attack is remote and requires user interaction (visiting the malicious page) but no authentication. The vulnerability allows an attacker to obtain sensitive information that should normally be protected. The vulnerability was patched in Chrome version 153.0.8010.36 released on September 8, 2026.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched: Chrome 153.0.8010.36 released to stable channel