Executive brief
Google Chrome's extension system failed to properly enforce security policies, allowing attackers who had already compromised the renderer process to execute arbitrary code outside the browser sandbox. An attacker would need to trick a user into visiting a malicious webpage and compromise the renderer first, but successful exploitation would give full access to the user's system, potentially enabling data theft, malware installation, or complete device compromise.
Technical details
The vulnerability is an insufficient policy enforcement flaw in Google Chrome's extension handling mechanism affecting versions prior to 153.0.8010.36. The root cause lies in inadequate sandbox boundary enforcement—an attacker who has already compromised the renderer process can leverage social engineering (a crafted HTML page) to bypass the extension security model and execute arbitrary code outside the sandbox boundary. This requires the renderer to be compromised first, but once achieved, allows full arbitrary code execution with user privileges. The fix is available in Chrome 153.0.8010.36 and later.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched: Chrome 153.0.8010.36 released