Back

CRITICAL

chromium-browser: Google Chrome: Arbitrary code execution due to a race condition in USB

Published Aug 18, 2026

Description

Race condition in USB in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

Affected products

Remediation

Red Hat statement

This Important flaw in the `chromium-browser` package allows a remote attacker to execute arbitrary code outside the browser's sandbox. Exploitation requires a compromised renderer process and user interaction with a specially crafted HTML page, enabling a significant security bypass.

Weaknesses (2)

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Chrome
Published Aug 18, 2026
Updated Aug 20, 2026
Reserved Aug 18, 2026
CISA Vulnrichment
Updated Aug 19, 2026
NVD
Status Analyzed
Modified Aug 21, 2026
Red Hat
Severity Important
Public date Aug 18, 2026