Executive brief
Google Chrome's Omnibox (address bar and search component) contains an authorization flaw that allows remote attackers to bypass security controls and gain access to privileged browser pages. An attacker can craft a malicious HTML page that, when visited, escalates access to restricted functionality, potentially compromising browser security and user data.
Technical details
The vulnerability is an incorrect authorization flaw in the Omnibox component of Google Chrome versions prior to 153.0.8010.36. The root cause is insufficient access control validation that allows a remote attacker to bypass system access restrictions through a crafted HTML page. No user interaction beyond visiting the malicious page is required. An attacker can leverage this to access privileged pages normally protected by browser security policies. The vulnerability has been patched in Chrome 153.0.8010.36 and later.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched