CVE-2026-79014
Race condition in Autofill in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to byp
CVSS
4.3
Medio
EPSS
0.3%
p22
KEV
—
Exploit Today
7
0-100
Publicado: 25 ago 2026 · Última mod.: 28 ago 2026 · CWE-362
0.3%EPSS · 30 días0.3%
2026-08-262026-09-07
Race condition in Autofill in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-778947.0 ALT—
———Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Installer allows an authorized attacker to elevate privileges locally.5hCVE-2026-730057.0 ALT—
———Use after free in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.5hCVE-2026-705826.4 MED—
———Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Instrumentation allows an authorized attacker to elevate privileges locally.5hCVE-2026-700915.9 MED—
———Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to deny service over a network.5hCVE-2026-698278.1 ALT—
———Concurrent execution using shared resource with improper synchronization ('race condition') in DNS Server allows an unauthorized attacker to execute code over a network.5hCVE-2026-697997.8 ALT—
———Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hello allows an authorized attacker to elevate privileges locally.5h