Description
Inappropriate implementation in Safe Browsing in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a malicious file. (Chromium security severity: Low)
Published: 2026-06-04
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An inappropriate implementation in the Safe Browsing component of Google Chrome for macOS lets a remote attacker run arbitrary code by delivering a malicious file. The description indicates that the flaw exists in the file handling logic, and it is inferred that a user must open or otherwise interact with the malicious file for the exploit to trigger. Despite being marked low severity in Chromium’s internal tracking, the vulnerability grants full control over the affected system, threatening confidentiality, integrity, and availability.

Affected Systems

The issue affects Google Chrome on macOS versions earlier than 149.0.7827.53. Users running any older build of Chrome on macOS who receive and open a specially crafted file are exposed to the flaw. The product is Google Chrome, and the vulnerability is tied specifically to the Safe Browsing feature of the browser.

Risk and Exploitability

The EPSS score is < 1% and, with a CVSS score of 8.1, the vulnerability is not listed in CISA’s KEV catalog, so there is no evidence of active exploitation at the time of this analysis. Nevertheless, the likely attack vector requires an attacker to supply a malicious file and convince the target user to open it, making user interaction a prerequisite. Once triggered, the vulnerability allows full code execution within the browser process. Because the bug lies in Safe Browsing, routine file downloads or URL handling exposes the attack surface, but the exploit is not automatic and depends on user actions.

Generated by OpenCVE AI on June 7, 2026 at 15:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 149.0.7827.53 or later.
  • If an update cannot be applied immediately, temporarily disable Safe Browsing via policy or chrome://flags until the update is installed.
  • Ensure automatic updates are enabled so future patches are applied without manual intervention.

Generated by OpenCVE AI on June 7, 2026 at 15:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6325-1 chromium security update
History

Mon, 08 Jun 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos

Sun, 07 Jun 2026 12:15:00 +0000

Type Values Removed Values Added
Title chromium-browser: Inappropriate implementation in Safe Browsing
Weaknesses CWE-184
References
Metrics threat_severity

None

threat_severity

Low


Fri, 05 Jun 2026 16:15:00 +0000

Type Values Removed Values Added
Title Insecure Safe Browsing Implementation Allows Arbitrary Code Execution via Malicious File in Google Chrome on macOS

Fri, 05 Jun 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 05 Jun 2026 06:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Fri, 05 Jun 2026 05:15:00 +0000

Type Values Removed Values Added
Title Insecure Safe Browsing Implementation Allows Arbitrary Code Execution via Malicious File in Google Chrome on macOS
Weaknesses CWE-94

Thu, 04 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in Safe Browsing in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a malicious file. (Chromium security severity: Low)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-06-06T03:56:08.538Z

Reserved: 2026-06-04T17:10:57.454Z

Link: CVE-2026-11231

cve-icon Vulnrichment

Updated: 2026-06-05T13:40:34.999Z

cve-icon NVD

Status : Analyzed

Published: 2026-06-04T23:17:30.940

Modified: 2026-06-08T14:55:40.460

Link: CVE-2026-11231

cve-icon Redhat

Severity : Low

Publid Date: 2026-06-02T00:00:00Z

Links: CVE-2026-11231 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-06-07T16:00:04Z

Weaknesses
  • CWE-184

    Incomplete List of Disallowed Inputs

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')