Executive brief
Google Chrome contains a race condition in its core component that allows an attacker with control of the renderer process to bypass the browser's sandbox security feature and execute arbitrary code on the system. An attacker could exploit this via a specially crafted web page to gain full system access and compromise user data and operations.
Technical details
A race condition exists in Chrome's Core component prior to version 153.0.8010.47. The vulnerability requires the attacker to first compromise the renderer process (a sandboxed component), then exploit the race condition to break out of the sandbox and execute arbitrary code in a privileged context outside the sandbox. The attack vector is network-based through a malicious HTML page, but requires prior renderer compromise as a precondition. A patch is available in Chrome 153.0.8010.47 and later. This is classified as High severity by the Chromium project with a CVSS score of 8.3.
Affected products
- Google Chrome prior to 153.0.8010.47
Timeline
- 2026-09-15: disclosed
- 2026-09-15: patched: Fix released in Chrome 153.0.8010.47