Description
Inappropriate implementation in Safe Browsing in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a malicious file. (Chromium security severity: Low)
Published: 2026-06-04
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An inappropriate implementation in the Safe Browsing component of Google Chrome for macOS lets a remote attacker run arbitrary code by delivering a malicious file. The description indicates that the flaw exists in the file handling logic, and it is inferred that a user must open or otherwise interact with the malicious file for the exploit to trigger. Despite being marked low severity in Chromium’s internal tracking, the vulnerability grants full control over the affected system, threatening confidentiality, integrity, and availability.

Affected Systems

The issue affects Google Chrome on macOS versions earlier than 149.0.7827.53. Users running any older build of Chrome on macOS who receive and open a specially crafted file are exposed to the flaw. The product is Google Chrome, and the vulnerability is tied specifically to the Safe Browsing feature of the browser.

Risk and Exploitability

The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, so there is no evidence of active exploitation at the time of this analysis. Nevertheless, the likely attack vector requires an attacker to supply a malicious file and convince the target user to open it, making user interaction a prerequisite. Once triggered, the vulnerability allows full code execution within the browser process. Because the bug lies in Safe Browsing, routine file downloads or URL handling exposes the attack surface, but the exploit is not automatic and depends on user actions.

Generated by OpenCVE AI on June 5, 2026 at 04:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 149.0.7827.53 or later.
  • If an update cannot be applied immediately, temporarily disable Safe Browsing via policy or chrome://flags until the update is installed.
  • Ensure automatic updates are enabled so future patches are applied without manual intervention.

Generated by OpenCVE AI on June 5, 2026 at 04:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 05 Jun 2026 05:15:00 +0000

Type Values Removed Values Added
Title Insecure Safe Browsing Implementation Allows Arbitrary Code Execution via Malicious File in Google Chrome on macOS
Weaknesses CWE-94

Thu, 04 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in Safe Browsing in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a malicious file. (Chromium security severity: Low)
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-06-04T23:05:54.105Z

Reserved: 2026-06-04T17:10:57.454Z

Link: CVE-2026-11231

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-06-04T23:17:30.940

Modified: 2026-06-04T23:17:30.940

Link: CVE-2026-11231

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-05T05:00:13Z

Weaknesses