Executive brief
Google Chrome is a web browser used by billions of users to access websites and applications. A race condition vulnerability in its permissions system on Android allows attackers to bypass web origin policy restrictions through social engineering with a crafted HTML page, potentially enabling unauthorized access to sensitive browser features or cross-origin data.
Technical details
A race condition exists in the Permissions component of Google Chrome on Android prior to version 152.0.7977.65. The vulnerability allows a remote attacker to bypass web origin policy (same-origin policy) by exploiting a timing window during permission requests, using social engineering techniques to trick users into visiting a crafted HTML page. The attack requires user interaction (visiting a malicious page). The vulnerability is patched in Chrome 152.0.7977.65 and later versions.
Affected products
- Google Chrome prior to 152.0.7977.65 on Android
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65