Executive brief
Google Chrome is a web browser used by millions to access the internet. A race condition vulnerability in the browser's Core component could allow attackers to trick users via specially crafted web pages into bypassing web origin policy protections, potentially enabling unauthorized access to data or functionality across different websites.
Technical details
A race condition exists in the Core component of Google Chrome on Windows versions prior to 152.0.7977.65. The vulnerability allows a remote attacker leveraging social engineering to bypass web origin policy restrictions via a malicious HTML page. The race condition is a timing-dependent flaw where improper synchronization allows an attacker to violate same-origin policy isolation. The vulnerability requires user interaction (visiting a crafted page) and social engineering. The fix is available in Chrome 152.0.7977.65 and later for Windows.
Affected products
- Google Chrome prior to 152.0.7977.65 on Windows
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Chrome 152.0.7977.65 released for Windows