CVE-2026-79057

Google · Chrome

A race condition in Google Chrome for Android prior to version 152.0.7977.65 allows a local attacker to execute arbitrary code outside the sandbox via a co-installed application.

Executive summary

A critical race condition vulnerability in Google Chrome for Android enables local attackers to achieve sandbox escape and arbitrary code execution.

Vulnerability

This vulnerability is a race condition (CWE-367) occurring in the Start component of Google Chrome on Android. The flaw allows an unauthenticated local attacker to leverage social engineering and a co-installed application to break out of the browser sandbox and execute arbitrary code.

Business impact

The ability to execute code outside the browser sandbox represents a significant compromise of the mobile device security model. An attacker could potentially gain full control over the application environment, leading to data theft or unauthorized system access. Given the CVSS score of 8.1, this is classified as a high severity risk that requires immediate attention to prevent device-level exploitation.

Remediation

Immediate Action: Update Google Chrome on all affected Android devices to version 152.0.7977.65 or later immediately.

Proactive Monitoring: Review mobile device management (MDM) logs for the installation of unauthorized or suspicious applications that could be leveraged as a vector for this race condition.

Compensating Controls: Ensure that Google Play Protect is enabled on all Android devices to assist in the detection and removal of potentially harmful applications that may attempt to exploit this vulnerability.

Exploitation status

Public Exploit Available: No

Analyst recommendation

This vulnerability presents a serious risk to the integrity of the Android operating environment by bypassing the browser sandbox. IT administrators should prioritize the deployment of the latest Chrome update across their mobile fleet. Users should also exercise caution regarding the installation of untrusted applications from non-official sources to reduce the likelihood of a successful attack.

More Google CVEs

Sources