Executive brief
Google Chrome's installer component contains improper state validation that could allow an attacker to bypass system access restrictions through a crafted HTML page. This could potentially enable unauthorized users to escalate privileges or circumvent security controls during the installation process.
Technical details
The vulnerability is an improper state validation flaw in Google Chrome's Installer component (Chromium severity: Medium). An attacker can craft a malicious HTML page that, when processed during the installation or update workflow, bypasses system access restrictions that are normally enforced. The attack requires user interaction (visiting a crafted page) and network access. A successful exploit allows an attacker to circumvent installer-level security controls. The fix is available in Chrome version 153.0.8010.36 and later.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched: Chrome 153.0.8010.36 released