Junglewise Threat Intelligence

CVE-2026-12022: Google Chrome race condition in Safe Browsing

CVE-2026-12022 · Severity: info · Published 2026-06-11

Technologies: Google Chrome. Vendors: Google.

Executive brief

A race condition vulnerability exists in Google Chrome's Safe Browsing feature on macOS. Safe Browsing is a security service that identifies and warns users about malicious websites and files. If exploited, an attacker who has already partially compromised the browser could bypass security protections (the sandbox) to gain broader access to the underlying operating system, potentially leading to full system compromise or data theft.

Technical details

A race condition (CWE-362) exists in the Safe Browsing component of Google Chrome for macOS. The vulnerability is reachable by a remote attacker who has already achieved code execution within a compromised renderer process. By exploiting improper synchronization during the handling of malicious files, the attacker can bypass the browser's sandbox boundaries. This allows the attacker to execute arbitrary code with the privileges of the browser process on the host operating system. The issue is resolved in Chrome version 149.0.7827.115 for Mac.

Affected products

  • Google Chrome prior to 149.0.7827.115

Timeline

  • 2026-05-27: disclosed: Reported to Google by internal researchers.
  • 2026-06-11: patched: Stable channel update released.
  • 2026-06-11: advisory: NVD publication date.

References

Related threats