Executive brief
Google Chrome's Safebrowsing feature contains an authorization flaw that could allow an attacker to bypass system access restrictions through a crafted webpage and social engineering. An affected user visiting a malicious webpage could potentially gain unauthorized access to protected system resources, compromising device security and user data.
Technical details
An incorrect authorization vulnerability exists in the Safebrowsing component of Google Chrome versions prior to 153.0.8010.36. The flaw allows a remote attacker to bypass system access restrictions by leveraging social engineering tactics to trick a user into visiting a crafted HTML page. The vulnerability is rooted in insufficient authorization checks within the Safebrowsing service. No evidence of active exploitation in the wild has been reported. The vulnerability is patched in Chrome 153.0.8010.36 and later releases.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched: Chrome 153.0.8010.36 released