CVE-2026-78934: High Race condition in ReadAloud
Chromium: CVE-2026-78934 Race condition in ReadAloud
Other sources
Race condition in ReadAloud in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
— NVD
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 152.0.4191.53 - Upgrade
Upgrade
Google Chrome/Chromium (ReadAloud)to a version that resolves this vulnerability.Fixed in 152.0.7977.65
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What does an attacker need to exploit this issue?
The attacker needs to persuade a user to interact with a crafted HTML page. Successful exploitation can result in arbitrary code execution inside the Chrome sandbox.
Which Chrome versions should be prioritized for update?
Google Chrome versions earlier than 152.0.7977.65 are affected. Update affected installations to 152.0.7977.65 or later.