Junglewise Threat Intelligence

CVE-2026-79014: Google Chrome race condition in Autofill

CVE-2026-79014 · Severity: medium · CVSS 4.3 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's Autofill feature contains a race condition vulnerability that could allow a remote attacker to bypass web origin policy protections. While the attacker would need to have already compromised the browser's renderer process, successful exploitation could enable unauthorized access to user data from different websites, posing a risk to sensitive information protection.

Technical details

This is a race condition vulnerability in the Autofill component of Google Chrome prior to version 152.0.7977.65. The vulnerability allows a remote attacker who has already compromised the renderer process to bypass web origin policy restrictions via a crafted HTML page. The attack requires prior renderer process compromise, which is a significant precondition but could result from prior exploitation of other browser vulnerabilities. The vulnerability was patched in Chrome 152.0.7977.65 and later versions.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats