Executive brief
A vulnerability exists in the Google Chrome updater for Windows that could allow a local user to gain higher system privileges. By placing a malicious file on the system and timing it with the update process, an attacker could potentially execute code with elevated permissions. This could lead to a full compromise of the affected machine by someone who already has basic access to it.
Technical details
A race condition (CWE-362) exists in the Google Chrome Updater component on Windows platforms. The vulnerability is triggered when the updater improperly synchronizes access to shared resources, specifically during the handling of files during an update cycle. A local attacker with the ability to place a malicious file in a specific location can exploit this timing window to achieve privilege escalation. This issue was addressed in Google Chrome version 151.0.7922.72.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in version 151.0.7922.72
- 2026-07-30: disclosed