Junglewise Threat Intelligence

CVE-2026-87554: Google Chrome race condition in Chromoting sandbox escape

CVE-2026-87554 · Severity: high · CVSS 8.1 · Published 2026-09-09

Executive brief

Google Chrome's Chromoting remote desktop feature on Windows contained a race condition that allowed a local attacker to break out of Chrome's security sandbox and run arbitrary code with elevated privileges. An attacker with local access to a machine could exploit this to completely compromise the system.

Technical details

A race condition vulnerability exists in the Chromoting component of Google Chrome on Windows prior to version 153.0.8010.36. The vulnerability allows a local attacker to execute arbitrary code outside the Chrome sandbox through a local program. This is a privilege escalation / sandbox escape issue with a network-adjacent or local attack vector. The attacker must have local access to the affected system. Google has patched the vulnerability in Chrome 153.0.8010.36 and later versions, released on September 8, 2026.

Affected products

  • Google Chrome prior to 153.0.8010.36 on Windows

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Chrome 153.0.8010.36 released

References

Related threats