Junglewise Threat Intelligence

CVE-2026-79263: Google Chrome race condition in Extensions

CVE-2026-79263 · Severity: high · CVSS 8.1 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Chrome's extension system contains a race condition that allows attackers to execute arbitrary code within the browser's sandbox through specially crafted network traffic. An attacker can exploit this to execute malicious code without user interaction, potentially leading to data theft, credential compromise, or further system infiltration.

Technical details

A race condition exists in the Extensions component of Google Chrome prior to version 152.0.7977.65. The vulnerability allows a remote attacker to execute arbitrary code inside the sandbox by sending crafted network traffic. The race condition likely stems from improper synchronization or timing issues in the extension loading or execution mechanism. No authentication is required; network-level exploitation is possible. Exploitation grants code execution within the browser's sandboxed environment, which, while constrained, can still be leveraged for information disclosure or further exploitation. The fix is available in Chrome 152.0.7977.65 and later.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats