Description
Race condition in DataTransfer in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-09-09
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Information Disclosure
Action: Apply Patch
AI Analysis

Impact

Race condition in the DataTransfer feature of Google Chrome allows a remote attacker to obtain sensitive information by serving a specially crafted HTML page. The flaw permits the attacker to read data that should otherwise be inaccessible, creating a breach of confidentiality caused by a timing issue that incorrectly synchronizes data access.

Affected Systems

All users running Google Chrome versions older than 153.0.8010.36 are affected, including the stable channel releases listed in the Google Chrome release notes. The issue exists in the Windows, macOS, Linux, and Chrome OS builds of the browser.

Risk and Exploitability

The vulnerability has a CVSS score of 6.5, classified as low severity by Chromium, and the EPSS score is less than 1%, indicating a low probability of exploitation. It is not listed in CISA’s KEV catalog. Exploitation requires the victim to open a malicious web page and is socially engineered; thus the attack vector is remote via the network and depends on user cooperation. No known public exploits are reported, but the remote nature and lack of local privilege escalation make it a potential target for targeted phishing campaigns.

Generated by OpenCVE AI on September 9, 2026 at 17:34 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Google Chrome version 153.0.8010.36 or later
  • Use site permissions to restrict clipboard access for untrusted sites
  • Avoid opening suspicious HTML pages and remain cautious about social engineering

Generated by OpenCVE AI on September 9, 2026 at 17:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Wed, 09 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Vendors & Products Google
Google chrome

Wed, 09 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Title Race Condition in DataTransfer Allows Remote Information Disclosure via Crafted HTML Pages

Wed, 09 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 07:15:00 +0000

Type Values Removed Values Added
Title Race Condition in DataTransfer Allows Remote Information Disclosure via Crafted HTML Pages

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Race condition in DataTransfer in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-367
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-09T14:36:19.230Z

Reserved: 2026-09-08T22:39:26.640Z

Link: CVE-2026-87523

cve-icon Vulnrichment

Updated: 2026-09-09T14:35:39.425Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:09.470

Modified: 2026-09-09T18:02:22.530

Link: CVE-2026-87523

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T00:45:11Z

Weaknesses
  • CWE-367

    Time-of-check Time-of-use (TOCTOU) Race Condition