CVE-2026-17712
Google · Chrome
A race condition exists in the Skia graphics library within Google Chrome on Mac, which could allow a remote attacker to perform unauthorized actions via a specially crafted web page.
Executive summary
A race condition vulnerability in the Skia library of Google Chrome for Mac presents a high risk of remote code execution or system compromise.
Vulnerability
This is a race condition (CWE-362) within the Skia graphics library. An unauthenticated remote attacker can exploit this via a specially crafted web page that requires user interaction to trigger the vulnerability.
Business impact
The vulnerability carries a CVSS score of 8.8, indicating a high potential for severe impact. Successful exploitation could lead to full system compromise, including unauthorized data access and the execution of arbitrary code within the context of the application, posing a significant threat to organizational data integrity and system security.
Remediation
Immediate Action: Update Google Chrome to version 151.0.7922.72 or later immediately to incorporate the necessary security patches.
Proactive Monitoring: Monitor browser process logs for unexpected crashes or anomalous behavior that may indicate exploitation attempts.
Compensating Controls: Ensure that endpoint protection software is active and configured to detect malicious web content, as the exploit requires user interaction.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the high CVSS severity, organizations should prioritize the deployment of the latest Chrome update across all managed Mac workstations. Prompt patching is essential to closing this attack vector and preventing potential remote exploitation.