Executive brief
A security vulnerability exists in SketchUp 2026's Dynamic Components feature, which is used to create intelligent 3D models. By tricking a user into opening a specially crafted SketchUp (.SKP) file, an attacker can remotely execute commands on the user's computer and steal local files. This could lead to a total compromise of the user's workstation and the theft of sensitive design data or personal information.
Technical details
A Cross-Site Scripting (XSS) vulnerability exists in the Dynamic Components feature of Trimble SketchUp 2026. The flaw is caused by improper input sanitization within the component options window, which utilizes an embedded Internet Explorer 11 browser instance. An attacker can exploit this by crafting a malicious .SKP file containing embedded scripts; when a user opens the file and interacts with the component options, the script executes within the context of the application. This allows the attacker to bypass browser sandboxing to execute arbitrary system commands and exfiltrate local files. While the attack vector is local (requiring the user to open a file), the impact is high as it leads to full remote code execution (RCE).
Affected products
- Trimble SketchUp 2026 2026
Timeline
- 2026-05-21: disclosed: Vulnerability reported by Bugcrowd Inc.
- 2026-05-22: advisory: CVE-2026-9264 published to NVD.