CVE-2026-2319
7.5Google · Chrome
A race condition in the Google Chrome DevTools interface allows a remote attacker to achieve object corruption via malicious file interaction.
Executive summary
A race condition vulnerability in Google Chrome DevTools could allow a remote attacker to compromise system integrity through user-assisted interaction.
Vulnerability
This flaw is a race condition (CWE-362) within the DevTools component. An attacker can exploit this vulnerability if they successfully convince a user to perform specific UI gestures and install a malicious extension.
Business impact
The exploitation of this vulnerability can lead to object corruption, potentially resulting in unauthorized code execution or system instability. With a CVSS score of 7.5, this issue represents a significant risk, as it impacts the confidentiality, integrity, and availability of the user environment. Organizations relying on Chrome for business operations should prioritize updates to prevent potential browser-based attacks.
Remediation
Immediate Action: Update Google Chrome to version 145.0.7632.45 or later to resolve the underlying race condition.
Proactive Monitoring: Monitor endpoint security logs for unauthorized browser extension installations or unexpected DevTools activity.
Compensating Controls: Enforce organizational policies that restrict the installation of browser extensions to verified, enterprise-approved sources.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
While the requirement for user interaction reduces the probability of immediate mass exploitation, the potential for high impact necessitates prompt remediation. IT administrators should ensure all managed instances of Google Chrome are updated to the patched version as part of their standard patch management cycle.