Junglewise Threat Intelligence

CVE-2026-78894: Google Chrome race condition in Payments

CVE-2026-78894 · Severity: low · CVSS 3.1 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely-used web browser that processes user payments and handles sensitive financial transactions. A race condition vulnerability in Chrome's Payments component allows an attacker who has already compromised the browser's renderer process to leak cross-origin data through a crafted webpage, potentially exposing sensitive information from unrelated websites the user may visit.

Technical details

This is a race condition vulnerability in Google Chrome's Payments component that exists in versions prior to 152.0.7977.65. The vulnerability requires an attacker to have already compromised the renderer process, and can be triggered via a malicious HTML page. The race condition allows an attacker to leak cross-origin data, bypassing the browser's same-origin policy and exposing information from websites the user visits. The vulnerability was patched in Chrome 152.0.7977.65 and later versions released on August 25, 2026.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats