Junglewise Threat Intelligence

CVE-2026-91712: Google Chrome race condition in Extensions on Mac

CVE-2026-91712 · Severity: high · CVSS 8.3 · Published 2026-09-15

Executive brief

Google Chrome on Mac contains a race condition vulnerability in its Extensions system that could allow an attacker with access to the renderer process to execute arbitrary code outside the browser's sandbox. This could lead to complete system compromise and bypass of Chrome's security protections.

Technical details

A race condition exists in Chrome's Extensions implementation on macOS that allows an attacker who has already compromised the renderer process to escape the sandbox and execute arbitrary code with elevated privileges. The vulnerability is triggered via a crafted HTML page served to a user. The attack requires prior renderer process compromise, meaning the attacker must have already exploited a separate vulnerability to gain initial code execution within the browser. Chromium classified this as High severity. The issue is fixed in Chrome version 153.0.8010.47 and later.

Affected products

  • Google Chrome prior to 153.0.8010.47

Timeline

  • 2026-09-15: disclosed

References

Related threats