Executive brief
Google Chrome's extension system contained a missing authorization vulnerability that could allow a compromised renderer process to execute arbitrary code outside the sandbox. This could enable an attacker who has already compromised Chrome's rendering engine to break out of security boundaries and gain full system-level access to a user's computer.
Technical details
The vulnerability is a missing authorization flaw in the Chrome Extensions component. It affects Chrome versions prior to 153.0.8010.36 and requires an attacker to have already compromised the renderer process. By sending crafted network traffic, an attacker can bypass extension authorization checks and execute arbitrary code outside the sandbox environment, effectively defeating Chrome's sandboxing security boundary. The vulnerability is fixed in Chrome 153.0.8010.36 and later.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed