Executive brief
Google Chrome on Windows contains an authorization flaw in its auto-update mechanism that allows a local attacker to bypass sandboxing protections and execute arbitrary code with elevated privileges. This could enable an attacker with local system access to compromise the browser and gain access to sensitive user data or further attack the system.
Technical details
The vulnerability is an incorrect authorization issue in Chrome's Updater component on Windows prior to version 153.0.8010.36. A local attacker can exploit insufficient authorization checks in the update process to execute arbitrary code outside the browser sandbox via a malicious local program. This requires local system access but allows full code execution with the privileges of the updater process, potentially bypassing sandbox restrictions that normally confine the browser.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-08: disclosed
- 2026-09-08: patched: Fixed in Chrome 153.0.8010.36