Executive brief
Google Chrome's Transactions Platform contains a race condition that could allow attackers to bypass system access restrictions on Android devices. An attacker could exploit this vulnerability by crafting a malicious HTML page and tricking a user into visiting it, potentially gaining unauthorized access to the device's restricted functions or data.
Technical details
A race condition exists in Google Chrome's Transactions Platform on Android that permits bypass of system access restrictions. The vulnerability resides in the transaction processing logic where a timing gap between access checks and resource access allows an attacker to circumvent authorization controls. Exploitation requires social engineering to trick a user into visiting a crafted HTML page via the network; no special privileges or authentication are required. A successful exploit could allow an attacker to access restricted system functions or transaction-related data on the affected Android device. The vulnerability is patched in Chrome version 152.0.7977.65 and later.
Affected products
- Google Chrome Prior to 152.0.7977.65 on Android
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Chrome 152.0.7977.65