Impact
DataTransfer is a web API that represents data being transferred. In Chrome versions prior to 150.0.7871.47, a race condition in this API allows a remote attacker to read contents from the browser process memory by interacting with a DataTransfer object before its internal state is finalized. This flaw, classified as CWE-362, permits the attacker to obtain potentially sensitive information via a crafted HTML page. The impact is information disclosure without requiring local privileges.
Affected Systems
Google Chrome versions earlier than 150.0.7871.47 are affected. The issue impacts all platforms where Chrome is installed and used to view HTML content, as the vulnerability is triggered purely in the browser rendering engine. Users who continue to run older Chrome releases remain vulnerable until they upgrade to a newer build that contains the race condition fix.
Risk and Exploitability
The likely attack vector is remote, via a malicious web page that the user visits. In order to exploit the flaw the attacker must first trick the victim into accessing a crafted page, after which the race in DataTransfer can expose memory contents. The exploit does not require elevated local privileges and can be performed against any user who loads the malicious page. While the EPSS score is less than 1% and the vulnerability is not listed in CISA’s KEV catalog, the CVSS score of 5.3 indicates a medium severity rating suggestive of a moderate risk if the vulnerability is actively targeted. A successful exploitation would result in the disclosure of potentially sensitive data, compromising confidentiality of the affected user.
OpenCVE Enrichment
Debian DLA
Debian DSA