Junglewise Threat Intelligence

CVE-2026-93380: Google Chrome race condition in FileSystem

CVE-2026-93380 · Severity: low · CVSS 3.1 · Published 2026-09-17

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome contains a race condition vulnerability in its FileSystem component that could allow an attacker who has already compromised the browser's renderer process to bypass system access restrictions through social engineering. This could lead to unauthorized access to files and data on the system where Chrome is running.

Technical details

A race condition exists in the FileSystem component of Google Chrome prior to version 153.0.8010.52. The vulnerability requires that an attacker has already compromised the browser's renderer process and can leverage social engineering to trick the user into interacting with a crafted HTML page. The race condition allows bypass of system access restrictions, potentially enabling unauthorized file access. The vulnerability was patched in Chrome 153.0.8010.52 and later versions.

Affected products

  • Google Chrome before 153.0.8010.52

Timeline

  • 2026-09-17: disclosed
  • 2026-09-17: patched

References

Related threats