Impact
Race condition in the DataTransfer feature of Google Chrome allows a remote attacker to obtain sensitive information by serving a specially crafted HTML page. The flaw permits the attacker to read data that should otherwise be inaccessible, creating a breach of confidentiality caused by a timing issue that incorrectly synchronizes data access.
Affected Systems
All users running Google Chrome versions older than 153.0.8010.36 are affected, including the stable channel releases listed in the Google Chrome release notes. The issue exists in the Windows, macOS, Linux, and Chrome OS builds of the browser.
Risk and Exploitability
The vulnerability has a CVSS score of 6.5, classified as low severity by Chromium, and the EPSS score is less than 1%, indicating a low probability of exploitation. It is not listed in CISA’s KEV catalog. Exploitation requires the victim to open a malicious web page and is socially engineered; thus the attack vector is remote via the network and depends on user cooperation. No known public exploits are reported, but the remote nature and lack of local privilege escalation make it a potential target for targeted phishing campaigns.
OpenCVE Enrichment
Debian DLA
Debian DSA