Junglewise Threat Intelligence

CVE-2026-79155: Google Chrome race condition in FileSystem sandbox escape

CVE-2026-79155 · Severity: high · CVSS 8.3 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's FileSystem component contained a race condition that could allow an attacker who has already compromised the browser's renderer process to bypass the sandbox and execute arbitrary code on the user's computer. A successful exploit requires the attacker to first compromise the renderer through a crafted webpage, then exploit this race condition to break out of the security sandbox—a two-stage attack that could lead to full system compromise.

Technical details

A race condition vulnerability in Chrome's FileSystem component allows a remote attacker who has already compromised the renderer process to bypass the sandbox and potentially execute arbitrary code outside the sandbox boundary. The vulnerability is triggered via a crafted HTML page and requires the attacker to have first achieved code execution within the renderer process. The race condition likely stems from improper synchronization or timing-dependent logic in FileSystem operations. This vulnerability was reported by Google on 2026-06-10 and was patched in Chrome version 152.0.7977.65 for Windows, Mac, and Linux platforms.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Chrome 152.0.7977.65

References

Related threats