Impact
A race condition in the WebProtect component of Google Chrome, present before version 152.0.7977.65, allows a remote attacker who already holds a compromise of the renderer process to pull sensitive data from a crafted HTML page. The flaw is a classic timing issue that leads to leakage of confidential information. The weakness is catalogued as CWE‑367, a race condition that permits unauthorized access to protected data.
Affected Systems
Google Chrome browsers running versions earlier than 152.0.7977.65 are affected. The vulnerability resides in the renderer process, which processes web content, so any Chrome installation using a vulnerable release is potentially susceptible.
Risk and Exploitability
The severity is listed as Medium by Chromium, and the CVSS score is 5.3. EPSS indicates an exploitation probability of less than 1%, and the vulnerability is not in the CISA KEV catalog, indicating it is not known to have been actively exploited in the wild. The attack path requires an adversary to first compromise the renderer process, typically by exploiting another vulnerability or having arbitrary web content executed. Once that precondition is met, the race can be triggered via a specially crafted HTML page to read restricted data. Overall, the risk is moderate: the attack is indirect, requires a renderer compromise, and there is no known public exploitation.
OpenCVE Enrichment
Debian DLA
Debian DSA