Description
Race condition in Transactions Platform in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-08-25
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Update Chrome
AI Analysis

Impact

A race condition exists in the Transactions Platform of Google Chrome on Android before version 152.0.7977.65. The flaw can be triggered by a maliciously crafted HTML page, allowing a remote attacker, with social engineering, to bypass system access restrictions. The weakness is a classic race condition and is identified as CWE‑367.

Affected Systems

Google Chrome for Android users running any version prior to 152.0.7977.65 are affected. The issue does not apply to Chrome versions newer than the stated cutoff or to non‑Android variants.

Risk and Exploitability

Chromium labels the vulnerability with low severity, and the CVSS score is 5.3. The EPSS score indicates a probability of exploitation less than 1 percent, and the issue is not listed in the CISA KEV catalog. The attack requires a user to open a specifically crafted HTML page, so it relies on social engineering and user interaction. Given the low severity rating and limited exploitation probability, the overall risk is considered moderate but still actionable.

Generated by OpenCVE AI on August 28, 2026 at 23:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to version 152.0.7977.65 or later.
  • Avoid opening unknown or suspicious HTML pages or links in Chrome until the patch is applied.
  • Keep the Android operating system and all applications up to date to reduce the overall attack surface.

Generated by OpenCVE AI on August 28, 2026 at 23:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Mon, 31 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Google android
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:-:*:*:*:*:*:*:*
Vendors & Products Google android

Fri, 28 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Title Race Condition in Chrome Transactions Platform Allows Access Restriction Bypass on Android

Fri, 28 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N'}


Tue, 25 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 25 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Title Race Condition in Chrome Transactions Platform Allows Access Restriction Bypass on Android

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Race condition in Transactions Platform in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-367
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-28T18:11:39.940Z

Reserved: 2026-08-25T06:09:04.539Z

Link: CVE-2026-79089

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:04.540

Modified: 2026-08-31T14:58:48.823

Link: CVE-2026-79089

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T23:15:04Z

Weaknesses
  • CWE-367

    Time-of-check Time-of-use (TOCTOU) Race Condition