Junglewise Threat Intelligence

CVE-2026-78915: Google Chrome race condition in Enterprise

CVE-2026-78915 · Severity: high · CVSS 7.5 · Published 2026-08-25

Technologies: Microsoft Windows, Google Chrome. Vendors: Microsoft, Google.

Executive brief

Google Chrome contains a race condition vulnerability in its Enterprise component that could allow an attacker on the same network to execute arbitrary code outside the browser's sandbox. This bypass of Chrome's security isolation could lead to complete system compromise, potentially giving attackers the ability to steal sensitive data, install malware, or take control of the affected computer.

Technical details

The vulnerability is a race condition in the Enterprise component of Google Chrome on Windows prior to version 152.0.7977.65. The race condition allows an adjacent attacker to execute arbitrary code outside the sandbox via crafted network traffic. No user interaction is required beyond having a vulnerable Chrome instance running on a network accessible to the attacker. The vulnerability enables sandbox escape, which is a critical capability as it circumvents Chrome's primary security boundary. The fix is available in Chrome 152.0.7977.65 and later.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Chrome 152.0.7977.65 released

References

Related threats