Junglewise Threat Intelligence

CVE-2026-78991: Google Chrome race condition in WebProtect

CVE-2026-78991 · Severity: medium · CVSS 5.3 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's WebProtect component contains a race condition vulnerability that allows an attacker who has already compromised Chrome's renderer process to access sensitive information on a user's system. This could expose passwords, browsing history, cached data, or other confidential information through a malicious webpage. The vulnerability requires prior compromise of the renderer, but poses a significant risk for users already targeted by other attacks.

Technical details

A race condition exists in Chrome's WebProtect module (versions prior to 152.0.7977.65) that can be exploited by an attacker with a compromised renderer process. The vulnerability allows information disclosure when the attacker crafts a specially designed HTML page that triggers the race condition. The attack requires that the renderer process has already been compromised, either through a separate exploit or initial breach. This is a medium-severity issue (CVSS 5.3) that enables elevation of data access privileges once code execution in the renderer is achieved. A fix is available in Chrome 152.0.7977.65 and later.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats