Junglewise Threat Intelligence

CVE-2026-79094: Google Chrome race condition in Workers bypass system access

CVE-2026-79094 · Severity: medium · CVSS 6.5 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a web browser used by billions of people worldwide to access web content and applications. A race condition vulnerability in Chrome's Workers feature allows a remote attacker to bypass system access restrictions by tricking a user into visiting a malicious webpage, potentially leading to unauthorized access to protected system resources or data.

Technical details

A race condition exists in Chrome's Workers implementation prior to version 152.0.7977.65, enabling a remote attacker to bypass system access restrictions. The vulnerability is triggered when a user visits a crafted HTML page that exploits a timing window in the Worker code path. The attack is network-reachable and requires user interaction (visiting a malicious website). Successful exploitation allows an attacker to circumvent sandbox or access control mechanisms. The vulnerability was patched in Chrome 152.0.7977.65 and later versions.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats