CVE-2026-17654

7.8

Google · Chrome

A race condition in the Google Chrome Updater for Mac allows local attackers to achieve OS-level privilege escalation by utilizing a malicious file.

Executive summary

A race condition vulnerability in the Google Chrome Updater for macOS allows local attackers to elevate privileges to the OS level, posing a significant risk to system integrity.

Vulnerability

The flaw is a race condition (CWE-362) within the update mechanism of the browser. This vulnerability allows an unprivileged local attacker to manipulate file operations to gain elevated system permissions.

Business impact

Successful exploitation of this vulnerability allows a local attacker to bypass standard security boundaries and gain OS-level control. Given the high CVSS score of 7.8, this poses a substantial risk to the confidentiality, integrity, and availability of affected workstations. Unauthorized privilege escalation can lead to full system compromise, data exfiltration, or the installation of persistent malicious software.

Remediation

Immediate Action: Update Google Chrome to version 151.0.7922.72 or later immediately to apply the security patch.

Proactive Monitoring: Monitor system logs for unauthorized attempts to access or modify updater binaries or temporary installation directories.

Compensating Controls: Ensure that standard user accounts have restricted permissions to sensitive system directories and enforce the use of endpoint detection and response tools to identify anomalous process behavior.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

This vulnerability represents a significant security risk for macOS environments utilizing Google Chrome. Administrators should prioritize the deployment of the latest browser version to all managed endpoints to remediate the underlying race condition. Failure to update may leave systems vulnerable to local privilege escalation attacks that could compromise the entire host operating system.

More Google CVEs

Sources