Executive brief
A race condition vulnerability exists in the Payments component of Google Chrome, a popular web browser. By tricking a user into visiting a specially crafted website, a remote attacker could potentially bypass the browser's security sandbox. This could allow the attacker to gain unauthorized access to the underlying operating system, potentially leading to data theft or the installation of malicious software.
Technical details
A race condition (CWE-362) exists in the Payments component of Google Chrome. The vulnerability is triggered when a remote attacker lures a user to a malicious HTML page designed to exploit improper synchronization during concurrent execution. Successful exploitation could allow the attacker to escape the Chromium sandbox and execute arbitrary code with the privileges of the user. Google has addressed this issue in version 148.0.7778.168 for Windows, Mac, and Linux. While the reported CVSS score is 8.3 (High), Chromium's internal severity rating for this sandbox escape is 'Critical'.
Affected products
- Google Chrome prior to 148.0.7778.168
Timeline
- 2026-04-17: disclosed: Reported to Google internally
- 2026-05-12: patched: Fixed in Chrome Stable Channel Update 148.0.7778.167/168
- 2026-05-14: advisory: NVD publication date