Junglewise Threat Intelligence

CVE-2026-87641: Google Chrome race condition in browser

CVE-2026-87641 · Severity: medium · CVSS 4.2 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome, the world's most widely used web browser, contains a race condition flaw that could allow an attacker to bypass system access restrictions by tricking a user into visiting a malicious webpage. An exploit would give an attacker unauthorized access to system resources that should be protected, potentially compromising user data or system security.

Technical details

A race condition vulnerability exists in the Browser component of Google Chrome prior to version 153.0.8010.36. The flaw allows a remote attacker to craft a malicious HTML page that, when visited, exploits a timing-dependent condition to bypass system access restrictions. The attack requires user interaction (visiting a crafted page) but does not require authentication. Successful exploitation could result in unauthorized system access or escalation of privileges. The vulnerability was patched in Chrome 153.0.8010.36 released on September 8, 2026.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched

References

Related threats