Junglewise Threat Intelligence

CVE-2026-12454: Google Chrome race condition in Safe Browsing

CVE-2026-12454 · Severity: high · CVSS 8.3 · Published 2026-06-17

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability in Google Chrome for Mac could allow an attacker to bypass the browser's security sandbox. This sandbox is a critical layer of defense that prevents malicious websites from accessing the rest of your computer. If exploited, an attacker who has already gained control of a browser tab could potentially access sensitive user data or execute unauthorized commands on the underlying operating system.

Technical details

A race condition (CWE-362) exists in the Safe Browsing component of Google Chrome for macOS. The vulnerability is reachable by a remote attacker who has already achieved code execution within a compromised renderer process. By enticing a user to visit a specially crafted HTML page, the attacker can exploit improper synchronization in shared resources to escape the Chromium sandbox. This allows for a transition from the restricted renderer process to the more privileged browser process or the host operating system. The issue is resolved in Chrome version 149.0.7827.155.

Affected products

  • Google Chrome prior to 149.0.7827.155

Timeline

  • 2026-05-27: disclosed: Reported by Google researchers
  • 2026-06-16: patched: Fixed in stable channel update 149.0.7827.155/.156
  • 2026-06-17: advisory: NVD publication date

References

Related threats