Junglewise Threat Intelligence

CVE-2026-79057: Google Chrome race condition in Start on Android

CVE-2026-79057 · Severity: high · CVSS 8.1 · Published 2026-08-25

Technologies: Google Chrome, Google Android. Vendors: Google.

Executive brief

Google Chrome on Android contains a race condition in the Start component that could allow an attacker with a malicious co-installed app to execute code outside the browser's security sandbox. An attacker would need to use social engineering to trick a user into installing a malicious app alongside Chrome. If successful, this could compromise device security and user data.

Technical details

A race condition exists in the Start component of Google Chrome on Android prior to version 152.0.7977.65. The vulnerability allows a local attacker to execute arbitrary code outside the sandbox via a co-installed app, requiring social engineering to trick the user into installing the malicious application. The attack leverages timing manipulation in the Start component to bypass sandbox restrictions. The vulnerability is patched in Chrome 152.0.7977.65 and later versions. Attack requires local access and a second malicious app, making it a local attack vector requiring user interaction.

Affected products

  • Google Chrome prior to 152.0.7977.65 on Android

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats