Executive brief
Google Chrome's Downloads feature contains incomplete cleanup logic that could allow an attacker to bypass system access restrictions. By crafting a malicious HTML page and using social engineering to trick a user into visiting it, an attacker could gain unauthorized access to the system. This could lead to data theft, malware installation, or unauthorized system access.
Technical details
This vulnerability is a logic flaw in Google Chrome's Downloads component where incomplete cleanup fails to properly sanitize or remove sensitive state between operations. An attacker can craft a malicious HTML page that, when visited by a user, exploits this cleanup deficiency to bypass system access restrictions or security boundaries. The attack requires user interaction (visiting the crafted page via social engineering) and network access, but no authentication is required. The vulnerability was fixed in Chrome version 153.0.8010.36, released in September 2026.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched