Executive brief
Google Chrome is a web browser used by billions of people worldwide to access web content and applications. A race condition vulnerability in Chrome's Workers feature allows a remote attacker to bypass system access restrictions by tricking a user into visiting a malicious webpage, potentially leading to unauthorized access to protected system resources or data.
Technical details
A race condition exists in Chrome's Workers implementation prior to version 152.0.7977.65, enabling a remote attacker to bypass system access restrictions. The vulnerability is triggered when a user visits a crafted HTML page that exploits a timing window in the Worker code path. The attack is network-reachable and requires user interaction (visiting a malicious website). Successful exploitation allows an attacker to circumvent sandbox or access control mechanisms. The vulnerability was patched in Chrome 152.0.7977.65 and later versions.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65