Junglewise Threat Intelligence

CVE-2026-91748: Google Chrome race condition in Extensions on Mac

CVE-2026-91748 · Severity: high · CVSS 8.3 · Published 2026-09-15

Executive brief

Google Chrome for Mac contains a race condition vulnerability in the Extensions system that could allow an attacker who has already compromised the browser's renderer process to execute arbitrary code outside the sandbox. The attack requires social engineering to trick the user into interacting with a malicious UI element. This could lead to complete compromise of the system and user data.

Technical details

A race condition exists in the Extensions component of Google Chrome on macOS prior to version 153.0.8010.47. The vulnerability requires two prerequisites: a compromised renderer process and social engineering to manipulate the user into performing a specific UI interaction. The race condition allows an attacker to escape the browser sandbox and execute arbitrary code with system privileges. The attack vector is local and requires user interaction. Google has patched this vulnerability in Chrome 153.0.8010.47 and later.

Affected products

  • Google Chrome prior to 153.0.8010.47

Timeline

  • 2026-09-15: disclosed
  • 2026-09-15: patched: Fixed in Chrome 153.0.8010.47

References

Related threats