CVE-2026-78934

Google · Chrome

A race condition vulnerability in the ReadAloud feature of Google Chrome allows a remote attacker to execute arbitrary code within the sandbox via a crafted HTML page.

Executive summary

Google Chrome versions prior to 152.0.7977.65 are susceptible to a high-severity race condition that permits arbitrary code execution through social engineering.

Vulnerability

The vulnerability is a race condition (CWE-362) located within the ReadAloud component. An unauthenticated remote attacker can trigger this flaw by enticing a user to navigate to a crafted HTML page, leading to code execution inside the browser sandbox.

Business impact

Successful exploitation of this vulnerability could result in full compromise of the browser session, potentially leading to unauthorized data access or further system compromise. While the CVSS score of 8.3 reflects a high risk, the requirement for user interaction and specific race conditions limits the probability of automated mass exploitation.

Remediation

Immediate Action: Update all instances of Google Chrome to version 152.0.7977.65 or later immediately.

Proactive Monitoring: Review browser crash logs and security event logs for anomalous activity related to the ReadAloud feature or unexpected process termination.

Compensating Controls: Utilize endpoint security solutions that monitor for suspicious child process spawning or unauthorized memory access attempts initiated by the browser.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the capability for arbitrary code execution, this vulnerability poses a significant risk to end-user workstations. Organizations should prioritize the deployment of the latest Chrome update across all managed devices to ensure the ReadAloud component is patched against this race condition.

More Google CVEs

Sources