Description
Inappropriate implementation in Updater in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: High)
Published: 2026-06-30
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Inappropriate implementation in the Google Chrome Updater on Windows allows a local attacker to place a malicious file that the updater processes, which can result in OS‑level privilege escalation. The flaw is characterized as CWE‑284. An attacker gains system‑wide privileges by exploiting the updater's incorrect file handling.

Affected Systems

All Windows installations of Google Chrome older than version 150.0.7871.47 are affected. The vulnerability exists in the updater component of those releases.

Risk and Exploitability

The EPSS score of less than 1% indicates a low probability of exploitation, and the vulnerability is not listed in CISA KEV. Nonetheless, with a CVSS score of 7.8 the flaw remains high severity for an attacker who can write to the updater’s directories. The attack requires local access and the ability to place a malicious file, after which the updater executes it with elevated privileges.

Generated by OpenCVE AI on July 22, 2026 at 15:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Chrome version 150.0.7871.47 or later.
  • If an upgrade cannot be applied immediately, uninstall or disable the Chrome Updater to prevent execution of malicious files.
  • Restrict write permissions to the Chrome Updater directories so that ordinary user accounts cannot place files there.

Generated by OpenCVE AI on July 22, 2026 at 15:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Wed, 22 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Local OS‑level Privilege Escalation via Chrome Updater

Wed, 15 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Local OS‑level Privilege Escalation via Chrome Updater

Mon, 13 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Malicious Updater File in Google Chrome on Windows

Sun, 12 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Malicious Updater File in Google Chrome on Windows

Sat, 11 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Local OS‑level privilege escalation via Chrome Updater on Windows

Fri, 10 Jul 2026 04:30:00 +0000

Type Values Removed Values Added
Title Local OS‑level privilege escalation via Chrome Updater on Windows

Thu, 09 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Title Chrome Updater allows local privilege escalation via malicious file

Tue, 07 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Title Chrome Updater allows local privilege escalation via malicious file

Mon, 06 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Chrome Updater Local Privilege Escalation on Windows

Mon, 06 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Chrome Updater Local Privilege Escalation on Windows

Sun, 05 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title Local OS‑Level Privilege Escalation via Chrome Updater on Windows

Sat, 04 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Local OS‑Level Privilege Escalation via Chrome Updater on Windows

Fri, 03 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Title Local OS‑level Privilege Escalation via Chrome Updater on Windows

Thu, 02 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Title Local OS‑level Privilege Escalation via Chrome Updater on Windows

Thu, 02 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Chrome Updater Exploit Enables Local Privilege Escalation

Wed, 01 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Chrome Updater Exploit Enables Local Privilege Escalation

Wed, 01 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Malicious File in Chrome Updater
Weaknesses CWE-732

Wed, 01 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Malicious File in Chrome Updater
Weaknesses CWE-732

Wed, 01 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in Updater in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: High)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-02T03:55:53.256Z

Reserved: 2026-06-29T23:03:20.856Z

Link: CVE-2026-13800

cve-icon Vulnrichment

Updated: 2026-07-01T13:41:25.047Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-22T16:00:04Z

Weaknesses