Executive brief
Google Chrome's ControlledFrame component failed to properly verify user permissions, allowing attackers to bypass system access restrictions through a social engineering attack involving a crafted web page. This could allow unauthorized access to restricted browser features or system resources that should have been blocked.
Technical details
This vulnerability is a missing authorization flaw in Chrome's ControlledFrame component. The root cause involves insufficient permission checks that allow attackers to bypass access control restrictions. The attack requires user interaction (clicking or interacting with a crafted HTML page delivered via social engineering), making the attack vector network-based but dependent on user action. An attacker can leverage this to circumvent system access restrictions and potentially access sensitive features or data. The vulnerability has been patched in Chrome 153.0.8010.36 and later versions.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-08: disclosed
- 2026-09-08: patched: Fixed in Chrome 153.0.8010.36