Executive brief
Google Chrome contains a missing authorization check in the LocalNetworkAccess component that allows a remote attacker with a compromised renderer process to bypass system access restrictions. An attacker could exploit this by serving a malicious HTML page to gain unauthorized access to local network resources on a user's system.
Technical details
This is an authorization bypass vulnerability in Chrome's LocalNetworkAccess component affecting versions prior to 153.0.8010.36. The root cause is missing authorization checks that fail to properly validate access to local network resources. The attack requires a compromised renderer process (sandboxed web content execution environment), which an attacker could achieve through other browser vulnerabilities or social engineering. A successful exploit allows an attacker to bypass system access restrictions and access restricted local network resources. The vulnerability was patched in Chrome 153.0.8010.36, released September 8, 2026.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched: Chrome 153.0.8010.36 released