Impact
A race condition in Chrome’s shared storage mechanism allows a remote attacker who has already compromised the renderer process to read data from another origin. The vulnerability can expose sensitive information stored by unrelated web content, compromising user privacy. The weakness is classified as CWE‑362: Race Condition.
Affected Systems
Google Chrome versions prior to 148.0.7778.96 are affected. The vulnerability applies to all desktop builds of the stable channel that include the shared storage feature.
Risk and Exploitability
EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, suggesting a moderate awareness of exploitation. The CVSS score of 3.1 indicates low severity. The attack requires the attacker to have already compromised the renderer process; the race condition then permits cross‑origin leakage. Public exploits have not been documented in the information supplied.
OpenCVE Enrichment