CVE-2026-91712: Race Condition
Published Sep 15, 2026
·Updated
Race condition in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Affected Software
1 affected component
Google Chrome<153.0.8010.47
Event History
Sep 15, 2026
CVE Published
via MITRE·08:41 PM
Data Sourced
via MITRE·08:41 PM
DescriptionWeakness
Frequently Asked Questions
1
What does an attacker need in order to exploit this issue?
The attacker must already have compromised the Chrome renderer process. They can then use a crafted HTML page to potentially execute arbitrary code outside Chrome’s sandbox.
2
Which systems and versions are affected?
The issue affects Google Chrome on macOS before version 153.0.8010.47.
3
Does visiting a crafted page alone compromise an otherwise intact browser?
The provided information describes exploitation after the renderer process has already been compromised. It does not state that a crafted HTML page alone can trigger the issue in an otherwise uncompromised renderer.