Executive brief
Google Chrome's browser component failed to properly authorize certain system access operations, allowing a remote attacker to bypass security restrictions by sending a specially crafted HTML page. This could enable an attacker to access restricted system resources or perform unauthorized operations without proper permission checks.
Technical details
A missing authorization vulnerability exists in Google Chrome's browser component prior to version 153.0.8010.36. The vulnerability allows a remote attacker to bypass system access restrictions through a crafted HTML page, indicating an authorization bypass in a network-accessible code path. The attack requires only that a user visit or interact with a malicious webpage and does not require prior authentication. An attacker exploiting this flaw could gain unauthorized access to system resources or features that should be restricted. The vulnerability was patched in Chrome 153.0.8010.36, released on September 8, 2026.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched