Description
Race condition in FileSystem in Google Chrome prior to 153.0.8010.52 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-17
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: Bypass of system access restrictions via a race condition
Action: Upgrade Chrome
AI Analysis

Impact

The vulnerability is a race condition (CWE-367) in the FileSystem module of Google Chrome that can be exploited by an attacker who has already gained partial control of the renderer process. By creating a specially crafted HTML page the attacker can race privileged and unprivileged threads, causing the renderer to access files outside its sandbox. This bypasses the operating‑system access restrictions and allows the attacker to read or modify local files, compromising the confidentiality and integrity of the user’s data.

Affected Systems

Google Chrome browsers on desktop in the stable channel running any build prior to version 153.0.8010.52. The flaw was fixed in the 153.0.8010.52 release and all later revisions.

Risk and Exploitability

The CVSS score of 3.1 indicates low overall severity, and the EPSS score less than 1% shows a very small chance of real‑world exploitation. Because the flaw requires a renderer process compromise first, the likelihood of a successful attack is low unless the attacker already succeeded in a social‑engineering attack to trigger the renderer. The vulnerability is not listed in CISA’s KEV catalog, indicating no known active exploitation. An attacker could obtain renderer control by convincing a user to load a targeted HTML page, after which the race condition would enable escape from sandbox file restrictions.

Generated by OpenCVE AI on September 19, 2026 at 18:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Google Chrome to version 153.0.8010.52 or later to close the race condition
  • Configure Chrome’s auto‑update settings so that security patches are installed automatically
  • Enforce strict content‑security‑policy and sandboxing for rendered pages to reduce the chance of renderer compromise

Generated by OpenCVE AI on September 19, 2026 at 18:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6508-1 chromium security update
History

Wed, 23 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Title chromium-browser: chromium-browser: Race condition in FileSystem
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 21 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Sat, 19 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Title FileSystem Race Condition Allows Bypassing OS Access Restrictions in Chrome

Sat, 19 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Title FileSystem Race Condition Allows Bypassing OS Access Restrictions in Chrome

Fri, 18 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 17 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
Description Race condition in FileSystem in Google Chrome prior to 153.0.8010.52 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-367
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-18T13:31:50.231Z

Reserved: 2026-09-17T19:34:48.214Z

Link: CVE-2026-93380

cve-icon Vulnrichment

Updated: 2026-09-18T13:24:13.999Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-17T21:17:55.320

Modified: 2026-09-21T11:00:34.710

Link: CVE-2026-93380

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-17T21:08:42Z

Links: CVE-2026-93380 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T18:45:14Z

Weaknesses
  • CWE-367

    Time-of-check Time-of-use (TOCTOU) Race Condition