Junglewise Threat Intelligence

CVE-2026-13882: Google Chrome race condition in USB sandbox escape

CVE-2026-13882 · Severity: info · CVSS 6.5 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A race condition exists in the USB component of Google Chrome. This vulnerability could allow a remote attacker who has already compromised the browser's rendering process to escape the security sandbox by tricking a user into visiting a specially crafted website. Successfully exploiting this would give the attacker broader access to the underlying operating system and user data.

Technical details

A race condition vulnerability exists in the WebUSB implementation within Google Chrome. The flaw is reachable by a remote attacker who has already achieved code execution within a compromised renderer process. By leveraging a crafted HTML page to trigger specific timing conditions during USB device interaction, the attacker can bypass sandbox restrictions. This could lead to full system compromise from the context of the browser. The issue is resolved in version 150.0.7871.47 and later.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched
  • 2026-06-30: advisory

References

Related threats