Executive brief
Google Chrome contains an authorization bypass vulnerability in its Loader component that allows attackers to bypass system access restrictions. An attacker could exploit this flaw by tricking a user into visiting a specially crafted webpage, potentially leading to unauthorized system access or privilege escalation on the victim's computer.
Technical details
This is an incorrect authorization vulnerability in Chrome's Loader component affecting versions prior to 153.0.8010.36. The vulnerability allows a remote attacker to bypass system access restrictions through social engineering attacks involving a crafted HTML page. The attack requires user interaction (clicking a malicious link or visiting a attacker-controlled page). No details on the underlying authorization flaw mechanism are provided in the advisory. The vulnerability is patched in Chrome 153.0.8010.36 and later.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched: Chrome 153.0.8010.36 released to stable channel