Description
Race condition in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)
Published: 2026-09-09
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Code Execution
Action: Apply Patch
AI Analysis

Impact

A race condition in the Chrome updater on Windows allows a local attacker to execute code outside the browser sandbox, granting them the ability to run arbitrary binaries or modify system settings. The vulnerability was evaluated by Chromium as high severity, reflecting the potentially critical impact on a user’s machine if exploited. The flaw arises when multiple threads access and modify shared state in the updater concurrently, enabling an attacker to influence its decision logic.

Affected Systems

Affected are installations of Google Chrome on Windows running any version prior to 153.0.8010.36. The specific patch that fixes the issue is distributed in the 153.0.8010.36 update and later releases.

Risk and Exploitability

The attack requires a local attacker with some user privileges to trigger the race, but once the race is exploited an attacker can escape the sandbox to obtain a full user’s access to system resources. The CVSS score is 8.1 and the EPSS score is < 1%. The vulnerability is not listed in the CISA KEV catalog, yet its high severity rating and the possibility of local privilege escalation present a significant risk in environments where users have local write access to Chrome’s updater executable.

Generated by OpenCVE AI on September 9, 2026 at 19:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Chrome version 153.0.8010.36 or later, which contains a synchronization fix in the updater.
  • Implement application whitelisting or use the Windows Defender Application Control to block unapproved instances of the updater from running.
  • Monitor the system for unexpected instantiation of chrome updater processes and enforce least‑privilege policies on accounts allowed to modify browser binaries.

Generated by OpenCVE AI on September 9, 2026 at 19:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Wed, 09 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Title Local Race Condition in Chrome Updater Enabling Code Execution Outside Sandbox

Wed, 09 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Microsoft
Microsoft windows
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Google
Google chrome
Microsoft
Microsoft windows

Wed, 09 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Title Local Race Condition in Chrome Updater Enabling Code Execution Outside Sandbox

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Race condition in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)
Weaknesses CWE-362
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-10T03:56:31.131Z

Reserved: 2026-09-08T22:37:53.563Z

Link: CVE-2026-87467

cve-icon Vulnrichment

Updated: 2026-09-09T14:23:11.423Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:03.227

Modified: 2026-09-10T04:18:20.243

Link: CVE-2026-87467

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T10:15:17Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')