CVE-2026-79089Medium· 5.3▾ SunlitRace condition in Transactions Platform in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severi…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake. The CVSS score shown above comes from the CISA ADP record, not NVD.
Exploit-prediction probability, daily snapshots since Sep 17.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CVEORG
Last analysed / modified upstream
0.2%
0.2% → 0.2%
Race condition in Transactions Platform in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
Chrome >= 152.0.7977.65 < 152.0.7977.65Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-79050Medium· 5.4chromium-browser: Google Chrome: System access restriction bypass via crafted HTML page (CVE-2026-79050)
CVE-2026-79136Medium· 5.4chromium-browser: Chromium: Web origin policy bypass via incorrect ServiceWorker authorization (CVE-2026-79136)
CVE-2026-79143Medium· 4.3chromium-browser: Google Chrome FileSystem: System access bypass through crafted HTML and social engineering (CVE-2026-79143)
CVE-2026-79251Medium· 6.5chromium-browser: Google Chrome: Web origin policy bypass via improper input validation (CVE-2026-79251)
CVE-2026-93380Low· 3.1Race condition in FileSystem in Google Chrome prior to 153.0.8010.52 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass system access restrictions via a crafted HTML page
CVE-2026-91748High· 8.3Race condition in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox …