Junglewise Threat Intelligence

CVE-2026-17654: Google Chrome race condition in Updater on macOS

CVE-2026-17654 · Severity: info · CVSS 0 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in the Google Chrome updater for macOS could allow a local user to gain elevated system privileges. By exploiting a timing issue (race condition) during the update process using a malicious file, an attacker could take full control of the operating system. This poses a significant risk to the confidentiality and integrity of all data on the affected machine.

Technical details

A race condition (CWE-362) exists in the Google Chrome Updater for macOS in versions prior to 151.0.7922.72. The vulnerability allows a local attacker to exploit improper synchronization during the update process by placing a malicious file in a shared resource path. Successful exploitation enables the attacker to escalate their privileges to the OS level. The issue was addressed in the Stable channel update to version 151.0.7922.72 for Mac.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-06-10: disclosed: Reported to Chromium by Google internal researchers
  • 2026-07-29: patched: Fixed in Chrome Stable channel version 151.0.7922.72
  • 2026-07-30: advisory: NVD publication date

References

Related threats