Race Condition Affecting chromium package, versions [,145.0.7632.45)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.2% (11th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-CHROMIUM-15272625
  • published12 Feb 2026
  • disclosed11 Feb 2026
  • creditUnknown

Introduced: 11 Feb 2026

CVE-2026-2319  (opens in a new tab)
CWE-362  (opens in a new tab)

How to fix?

Upgrade chromium to version 145.0.7632.45 or higher.

Overview

Affected versions of this package are vulnerable to Race Condition in DevTools due to the teardown of V8InspectorSession during DevToolsSession::Detach in the Blink inspector. When Detach runs, the session could be destroyed while a V8 session or agents are still on the stack, allowing use-after-free or object corruption. An attacker can potentially exploit this object corruption by convincing a user to perform specific UI gestures and install a malicious extension.

CVSS Base Scores

version 4.0
version 3.1