Impact
A race condition in the Workers implementation of Google Chrome versions prior to 152.0.7977.65 allows a remote attacker to bypass the browser’s system access restrictions with a specially crafted HTML page. The flaw, identified as CWE‑362, permits the attacker to elevate privileges or perform unauthorized operations without executing arbitrary code.
Affected Systems
The vulnerability affects all Google Chrome installations older than 152.0.7977.65. Users who have not installed the August 2026 release are exposed.
Risk and Exploitability
Chromium labels the issue as Medium severity and the CVSS score is 6.5. The vulnerability is not listed in the CISA KEV catalog. The EPSS score is <1%, indicating a very low probability of exploitation in the wild. Exploitation requires delivery of a malicious HTML page, a scenario that is readily achievable via normal web traffic. Because the condition relies on precise timing, successful exploitation may be difficult, but a successful attack would compromise browser isolation controls, raising the risk to moderate to high. Prompt remediation is recommended.
OpenCVE Enrichment
Debian DLA
Debian DSA