Executive brief
Google Chrome's FileSystem component contained a race condition that could allow an attacker who has already compromised the browser's renderer process to bypass the sandbox and execute arbitrary code on the user's computer. A successful exploit requires the attacker to first compromise the renderer through a crafted webpage, then exploit this race condition to break out of the security sandbox—a two-stage attack that could lead to full system compromise.
Technical details
A race condition vulnerability in Chrome's FileSystem component allows a remote attacker who has already compromised the renderer process to bypass the sandbox and potentially execute arbitrary code outside the sandbox boundary. The vulnerability is triggered via a crafted HTML page and requires the attacker to have first achieved code execution within the renderer process. The race condition likely stems from improper synchronization or timing-dependent logic in FileSystem operations. This vulnerability was reported by Google on 2026-06-10 and was patched in Chrome version 152.0.7977.65 for Windows, Mac, and Linux platforms.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Chrome 152.0.7977.65