Executive brief
Google Chrome's Safe Browsing feature, which protects users from malicious websites, contained a flaw in how it validated security states. An attacker could exploit this vulnerability by crafting a malicious HTML page that bypasses system access restrictions, potentially allowing unauthorized access to protected resources or system features.
Technical details
The vulnerability is an improper state validation flaw in the Safe Browsing component of Google Chrome prior to version 153.0.8010.36. A remote attacker can craft a malicious HTML page to exploit this vulnerability and bypass system access restrictions. No authentication or special user interaction is required beyond the victim visiting a crafted web page. The attack vector is network-based. This vulnerability was assigned a low severity rating by the Chromium security team and has been patched in Chrome 153.0.8010.36 and later versions.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched: Chrome 153.0.8010.36 released