Google Chrome DirectSockets Policy Enforcement Vulnerability Allowing Arbitrary Read/Write via Extensions

Vulnerability

A vulnerability exists in Google Chrome in the DirectSockets component, prior to version 148.0.7778.96. This issue stems from inadequate policy enforcement, which enables remote attackers to execute arbitrary read and write operations through a specially crafted Chrome extension.

Impact

Exploitation of this vulnerability could lead to unauthorized read and write access, allowing for potential manipulation of data or functionality within the browser.

Remediation

Users can update to Google Chrome version 148.0.7778.96 or later to address this vulnerability.

Added: May 6, 2026, 8:11 PM
Updated: May 6, 2026, 8:11 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
5.0
exploitability
4.2
remediation
7.7
relevance
7.6
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.