Junglewise Threat Intelligence

CVE-2026-6921: Google Chrome race condition in GPU sandbox escape

CVE-2026-6921 · Severity: high · CVSS 8.3 · Published 2026-04-23

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability in Google Chrome on Windows could allow a remote attacker to bypass the browser's security sandbox. By tricking a user into opening a specially crafted video file, an attacker could potentially gain unauthorized access to the underlying operating system. This could lead to the theft of sensitive data or the installation of malicious software outside of the browser's restricted environment.

Technical details

A race condition (CWE-362) exists within the GPU component of Google Chrome for Windows. The vulnerability is triggered when the browser processes a specially crafted video file, leading to improper synchronization during concurrent execution. A remote, unauthenticated attacker can exploit this flaw by convincing a user to visit a malicious website or open a malicious video, potentially achieving a sandbox escape to execute code with the privileges of the logged-in user. This issue was addressed in Chrome version 147.0.7727.117.

Affected products

  • Google Chrome Prior to 147.0.7727.117

Timeline

  • 2026-03-17: other: Reported by researcher soiax
  • 2026-04-22: patched: Fixed in Stable Channel Update 147.0.7727.116/117
  • 2026-04-23: disclosed: NVD publication date

References