Executive brief
Google Chrome on Android contains a race condition in the Start component that could allow an attacker with a malicious co-installed app to execute code outside the browser's security sandbox. An attacker would need to use social engineering to trick a user into installing a malicious app alongside Chrome. If successful, this could compromise device security and user data.
Technical details
A race condition exists in the Start component of Google Chrome on Android prior to version 152.0.7977.65. The vulnerability allows a local attacker to execute arbitrary code outside the sandbox via a co-installed app, requiring social engineering to trick the user into installing the malicious application. The attack leverages timing manipulation in the Start component to bypass sandbox restrictions. The vulnerability is patched in Chrome 152.0.7977.65 and later versions. Attack requires local access and a second malicious app, making it a local attack vector requiring user interaction.
Affected products
- Google Chrome prior to 152.0.7977.65 on Android
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65