Junglewise Threat Intelligence

CVE-2026-79071: Google Chrome race condition in GPU

CVE-2026-79071 · Severity: high · CVSS 8.3 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome contains a race condition in its GPU processing component that could allow an attacker to execute malicious code outside the browser's security sandbox. An attacker who has already compromised the browser's renderer process could exploit this flaw via a crafted webpage to gain elevated privileges and potentially steal data or install malware. This affects Chrome versions prior to 152.0.7977.65 on Windows, Mac, and Linux.

Technical details

A race condition exists in Chrome's GPU component that can be exploited by a remote attacker with a compromised renderer process. The vulnerability allows an attacker to execute arbitrary code outside the sandbox through a specially crafted HTML page. The attack requires prior compromise of the renderer process, making it a post-exploitation technique that could be chained with other renderer escapes. The vulnerability was assigned CVE-2026-79071 and is classified as High severity. A fix is available in Chrome 152.0.7977.65 and later.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched

References

Related threats