Junglewise Threat Intelligence

CVE-2026-79017: Google Chrome race condition in Extensions system access bypass

CVE-2026-79017 · Severity: medium · CVSS 6.5 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's extension system contains a race condition that allows a malicious extension to bypass system access restrictions. An attacker who can install a crafted Chrome extension could gain elevated privileges or access resources that should be restricted, potentially compromising user data or system security.

Technical details

A race condition exists in Chrome's Extensions system that allows circumvention of system access controls. The vulnerability is triggered when a malicious or compromised extension exploits timing gaps in Chrome's permission enforcement mechanism. An attacker needs to craft a Chrome extension and trick a user into installing it; the race condition can then be triggered to bypass sandbox restrictions or access system resources. This vulnerability affects Chrome versions prior to 152.0.7977.65, and patches are available in the stable release. The Chromium security team rated this as low severity internally, though the CVSS score reflects medium impact due to the potential for unauthorized access.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats