Description
Insufficient policy enforcement in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to bypass discretionary access control via a crafted Chrome Extension. (Chromium security severity: Medium)
Published: 2026-06-04
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Insufficient policy enforcement in Google Chrome extensions allows an attacker who convinces a user to install a malicious extension to bypass discretionary access control. The crafted extension can acquire privileges beyond those intended for an extension, potentially enabling the attacker to read, modify, or delete user data and execute restricted operations.

Affected Systems

Google Chrome versions prior to 149.0.7827.53 are affected. No additional vendor or product details are listed.

Risk and Exploitability

The vulnerability is exploitable once a user installs a malicious extension; the attacker must otherwise convince the user to do so. No EPSS score or KEV designation is available, so the likelihood of exploitation is unclear. The CVSS score is not provided, but the Chromium security severity is Medium, indicating a significant risk if the vulnerability is leveraged. No official patch or workaround is listed, so updating the browser is the primary mitigation strategy.

Generated by OpenCVE AI on June 5, 2026 at 01:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to the latest stable release
  • Disable or uninstall any untrusted or suspicious extensions
  • Monitor for future releases and apply patches as soon as they are available

Generated by OpenCVE AI on June 5, 2026 at 01:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 05 Jun 2026 07:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Fri, 05 Jun 2026 02:00:00 +0000

Type Values Removed Values Added
Title Malicious Extension Bypass of Access Control in Chrome Prior to 149.0.7827.53
Weaknesses CWE-284
CWE-285

Thu, 04 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Insufficient policy enforcement in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to bypass discretionary access control via a crafted Chrome Extension. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-06-04T23:04:13.573Z

Reserved: 2026-06-04T17:06:25.280Z

Link: CVE-2026-10997

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-06-04T23:17:03.357

Modified: 2026-06-05T15:02:59.990

Link: CVE-2026-10997

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-05T06:45:33Z

Weaknesses