Impact
A race condition in Chrome’s shared storage mechanism allows a remote attacker who has already compromised the renderer process to read data from another origin. The vulnerability exploits both race conditions (CWE‑362) and improper synchronization (CWE‑368), enabling the leakage of sensitive information stored by unrelated web content, and compromising user privacy.
Affected Systems
Google Chrome versions prior to 148.0.7778.96 are affected. The vulnerability applies to all desktop builds of the stable channel that include the shared storage feature.
Risk and Exploitability
EPSS score is less than 1% and the vulnerability is not listed in CISA’s KEV catalog, indicating low awareness of exploitation. The CVSS score of 3.1 reflects low severity. The attack requires the attacker to have already compromised the renderer process; the race condition then permits cross‑origin leakage. Public exploits have not been documented in the supplied information.
OpenCVE Enrichment
Debian DSA