Description
Insufficient validation of untrusted input in Downloads in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: High)
Published: 2026-06-30
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Google Chrome versions prior to 150.0.7871.47 contain an insufficient input validation flaw in the handling of downloaded extensions. The weakness, identified as CWE-20, permits an attacker who successfully convinces a user to install a malicious extension to execute arbitrary code on the user’s machine. Once the code runs, the attacker gains the privileges of the user, compromising confidentiality, integrity, and availability.

Affected Systems

All installations of Google Chrome older than version 150.0.7871.47 on Windows, macOS, and Linux are affected. The flaw applies to every channel—stable, beta, dev, or canary—that has not yet received the update, and to all platforms that run Chrome, as no channel or OS restriction is specified in the advisory.

Risk and Exploitability

The CVSS score of 8.1 classifies the vulnerability as high severity, but the EPSS score of less than 1% indicates a low likelihood of exploitation, and it is not listed in CISA’s KEV catalog. The vulnerability requires user interaction and social engineering to persuade the wearer to install a malicious extension. When the malicious payload is installed, it can be exploited to execute arbitrary code with the user’s privileges, potentially leading to full system compromise.

Generated by OpenCVE AI on August 12, 2026 at 01:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to version 150.0.7871.47 or later to apply the validation fix.
  • Deploy enterprise policies that restrict extension installation to a curated whitelist of approved developers or block all extensions not on the list.
  • Review and remove any unfamiliar, recently added, or suspicious extensions that could be malicious.

Generated by OpenCVE AI on August 12, 2026 at 01:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Wed, 12 Aug 2026 01:45:00 +0000

Type Values Removed Values Added
Title Chrome Extension Download Validation Flaw Allows Remote Code Execution

Sun, 02 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Title Chrome Extension Download Validation Flaw Allows Remote Code Execution

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Unvalidated Input in Chrome Downloads Enables Arbitrary Code Execution via Malicious Extension

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Unvalidated Input in Chrome Downloads Enables Arbitrary Code Execution via Malicious Extension

Wed, 22 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Insufficient validation allows malicious extension to execute arbitrary code in Chrome

Fri, 17 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Insufficient validation allows malicious extension to execute arbitrary code in Chrome

Thu, 16 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Insufficient Validation of Chrome Extensions Allows Remote Code Execution

Tue, 14 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Title Insufficient Validation of Chrome Extensions Allows Remote Code Execution

Mon, 13 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title Chrome Extension Download Validation Flaw Enables Remote Code Execution

Sun, 12 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Chrome Extension Download Validation Flaw Enables Remote Code Execution

Sat, 11 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Unvalidated Extension Downloads Enable Arbitrary Code Execution in Google Chrome

Thu, 09 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Title Unvalidated Extension Downloads Enable Arbitrary Code Execution in Google Chrome

Thu, 09 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Title Insufficient Validation in Chrome Extension Downloads Allows Arbitrary Code Execution

Tue, 07 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Title Insufficient Validation in Chrome Extension Downloads Allows Arbitrary Code Execution

Mon, 06 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Insufficient Validation in Chrome Downloads Enabling Arbitrary Code Execution via Malicious Extension

Sun, 05 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Insufficient Validation in Chrome Downloads Enabling Arbitrary Code Execution via Malicious Extension

Sun, 05 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Chrome Extension Install Vulnerability Allows Remote Code Execution

Sun, 05 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
Title Chrome Extension Install Vulnerability Allows Remote Code Execution

Sat, 04 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Chrome Extension Download Validation Flaw Allows Arbitrary Code Execution

Sat, 04 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Title Chrome Extension Download Validation Flaw Allows Arbitrary Code Execution

Fri, 03 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Title Insufficient Validation in Chrome Downloads Enables Malicious Extension Execution

Fri, 03 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Insufficient Validation in Chrome Downloads Enables Malicious Extension Execution

Thu, 02 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
Title Insufficient Download Validation Allows Arbitrary Code via Malicious Chrome Extension

Wed, 01 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Insufficient Download Validation Allows Arbitrary Code via Malicious Chrome Extension

Wed, 01 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Title Untrusted Input Handling Allows Arbitrary Code Execution via Malicious Chrome Extension

Wed, 01 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Untrusted Input Handling Allows Arbitrary Code Execution via Malicious Chrome Extension

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Insufficient validation of untrusted input in Downloads in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: High)
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-02T03:55:56.536Z

Reserved: 2026-06-29T23:03:18.644Z

Link: CVE-2026-13791

cve-icon Vulnrichment

Updated: 2026-07-01T13:44:17.555Z

cve-icon NVD

Status : Analyzed

Published: 2026-06-30T23:16:53.900

Modified: 2026-07-02T05:16:29.043

Link: CVE-2026-13791

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T01:30:07Z

Weaknesses