Description
Race in USB in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-06-30
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The race condition in Chrome’s USB handling, classified as CWE‑362, allows a remote attacker who already has execution a sandbox escape when the browser serves a crafted HTML page. This flaw can elevate code execution beyond the normally restricted browser sandbox, compromising the host system if the renderer is already compromised.

Affected Systems

All Google Chrome installations prior to version 150.0.7871.47 are affected, regardless of operating system.

Risk and Exploitability

The CVSS score of 9.6 indicates high severity. The EPSS score is reported as < 1%, and the vulnerability is not listed in CISA KEV. To exploit the flaw, an attacker must first gain a foothold in the renderer process, which is inferred from the description. Once such a foothold exists, supplying a maliciously crafted HTML document can trigger the race in USB handling, potentially breaking the sandbox and allowing elevated code execution.

Generated by OpenCVE AI on July 21, 2026 at 16:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Chrome to version 150.0.7871.47 or later as soon as possible.
  • If maintaining Chrome source or custom builds, ensure USB handling code uses proper synchronization primitives to guard against concurrent access, following CWE‑362 mitigation guidelines such as lock usage to avoid race conditions.
  • Enforce the Update or Group Policy.
  • Restrict USB device access for untrusted sites via browser policies or device management to reduce the attack surface for race condition exploitation.
  • Monitor browser logs and network activity for suspicious USB request patterns and block malicious sites that could deliver crafted HTML.

Generated by OpenCVE AI on July 21, 2026 at 16:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Tue, 21 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Title Race Condition in Chrome USB Handling Leads to Potential Sandbox Escape

Wed, 15 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Race Condition in Chrome USB Handling Leads to Potential Sandbox Escape

Mon, 13 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Title USB Handling Race Condition Enables Sandbox Escape via Crafted HTML

Sun, 12 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title USB Handling Race Condition Enables Sandbox Escape via Crafted HTML

Sat, 11 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title USB Handling Race Condition Enables Sandbox Escape in Google Chrome

Thu, 09 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Title USB Handling Race Condition Enables Sandbox Escape in Google Chrome

Thu, 09 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Race Condition in Chrome USB Handling Allows Sandbox Escape via Crafted HTML

Wed, 08 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Race Condition in Chrome USB Handling Allows Sandbox Escape via Crafted HTML

Tue, 07 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Title Race Condition in USB Handling Allows Sandbox Escape

Tue, 07 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Title Race Condition in USB Handling Allows Sandbox Escape

Mon, 06 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Race Condition in Chrome USB Handling Enables Sandbox Escape

Sun, 05 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title Race Condition in Chrome USB Handling Enables Sandbox Escape

Sun, 05 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Title Race Condition in Chrome USB Handling Enables Sandbox Escape

Sun, 05 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Title Race Condition in Chrome USB Handling Enables Sandbox Escape

Sat, 04 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Title Race Condition in Chrome USB Handling Enables Sandbox Escape via Crafted HTML

Sat, 04 Jul 2026 08:00:00 +0000

Type Values Removed Values Added
Title Race Condition in Chrome USB Handling Enables Sandbox Escape via Crafted HTML

Fri, 03 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Race Condition in Chrome USB Handling Enables Sandbox Escape

Thu, 02 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
Title Race Condition in Chrome USB Handling Enables Sandbox Escape

Thu, 02 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Race Condition in USB Handling Allows Sandbox Escape in Google Chrome

Thu, 02 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Race Condition in USB Handling Allows Sandbox Escape in Google Chrome

Wed, 01 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Race Condition in USB Handling Enables Sandbox Escape in Google Chrome

Wed, 01 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Race Condition in USB Handling Enables Sandbox Escape in Google Chrome

Wed, 01 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Title Race Condition in USB Handling Enables Sandbox Escape in Google Chrome
Weaknesses CWE-285
CWE-362

Wed, 01 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Race Condition in USB Handling Enables Sandbox Escape in Google Chrome
Weaknesses CWE-285
CWE-362

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Race in USB in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T15:02:49.036Z

Reserved: 2026-06-29T23:03:41.332Z

Link: CVE-2026-13882

cve-icon Vulnrichment

Updated: 2026-07-01T15:02:41.208Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T17:00:04Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')