Executive brief
Google Chrome is a web browser used by millions of users worldwide to access the internet. A race condition vulnerability in the Editing component could allow an attacker to trick users into visiting a malicious webpage, potentially exposing sensitive information. The issue affects Chrome versions before 152.0.7977.65 and requires social engineering to exploit.
Technical details
A race condition exists in the Editing component of Google Chrome prior to version 152.0.7977.65. The vulnerability is triggered when processing a crafted HTML page and allows remote attackers to obtain sensitive information through social engineering tactics (e.g., tricking users into visiting malicious sites). Attack vector is network-based; no special authentication or elevated privileges are required, but user interaction (visiting the malicious page) is necessary. The vulnerability was patched in Chrome 152.0.7977.65. Google assigned it a Low severity rating in the Chromium security framework, though the CVSS score is 5.3 (Medium).
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65