Description
Race in WebAudio in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-05-28
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A race condition exists in the WebAudio implementation of Google Chrome before version 148.0.7778.216. The flaw allows a malicious web page to trigger concurrent operations that lead to arbitrary code execution inside the browser’s sandboxed process. It is classified as a concurrency control weakness (CWE‑362) and generally requires the attacker to interleave interactions in a specific order, which is why this is a higher‑level security issue than a typical input validation bug. As the code runs with the privileges of the browser process, a successful exploitation could allow information leakage or the launch of further attacks if the sandbox can be broken.

Affected Systems

The vulnerability affects all installations of Google Chrome that are not updated beyond version 148.0.7778.216. It applies to the stable channel releases on all supported operating systems. Users who remain on older builds of Chrome are at risk, regardless of the device or OS they use, unless they have mitigated other conditions that are not specified.

Risk and Exploitability

The likely attack vector is serving a crafted HTML page that triggers the race condition in a victim’s browser (inferred from the description). The CVSS score is 7.5, indicating high severity. The EPSS score is less than 1%, implying low current exploitation probability, but the existence of a simple exploit path suggests that opportunistic attackers could deploy it when they are ready. The vulnerability is not listed in the CISA KEV catalog, which means no confirmed exploitation in the wild has been reported, yet the concurrency flaw could still be leveraged by attackers with the appropriate web skills.

Generated by OpenCVE AI on May 29, 2026 at 15:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 148.0.7778.216 or later, which contains the race condition fix.
  • If an immediate upgrade is not possible, disable the WebAudio API for potentially untrusted sites using content‑security‑policy or the browser’s site‑and‑plugin management settings to reduce exposure while a patch is pending. (This step is a temporary workaround.)
  • Enable automatic updates in Chrome so that security patches are applied as soon as they are released.

Generated by OpenCVE AI on May 29, 2026 at 15:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 29 May 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows

Fri, 29 May 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Fri, 29 May 2026 12:15:00 +0000

Type Values Removed Values Added
Title Race Condition in WebAudio Enabling Remote Code Execution chromium-browser: Race in WebAudio
Weaknesses CWE-368
References
Metrics threat_severity

None

cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

threat_severity

Important


Thu, 28 May 2026 23:45:00 +0000

Type Values Removed Values Added
Title Race Condition in WebAudio Enabling Remote Code Execution
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 28 May 2026 22:45:00 +0000

Type Values Removed Values Added
Description Race in WebAudio in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-362
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-05-29T12:28:54.772Z

Reserved: 2026-05-28T17:25:12.612Z

Link: CVE-2026-10006

cve-icon Vulnrichment

Updated: 2026-05-29T12:28:48.530Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-28T23:16:42.430

Modified: 2026-05-29T17:18:09.337

Link: CVE-2026-10006

cve-icon Redhat

Severity : Important

Publid Date: 2026-05-27T00:00:00Z

Links: CVE-2026-10006 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-05-29T16:00:15Z

Weaknesses