Impact
A race condition in PlatformIntegration on macOS allowed a remote attacker who had already infected the renderer process and used social engineering to deliver a crafted HTML page to obtain sensitive information. The flaw permits leakage of data that the renderer can access, undermining confidentiality for users who interact with malicious or unsuspecting web content. It is a concurrency control failure, classified under CWE-367.
Affected Systems
Google Chrome for macOS versions earlier than 153.0.8010.47 is vulnerable. The issue does not affect other operating systems or newer releases beyond the stated version.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, but the Chromium project rates it highly due to the potential for significant data loss. The EPSS score of less than 1% suggests a low probability of immediate exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires a prior compromise of the renderer process—likely through another flaw or unsafe content—and relies on social engineering to deliver the malicious HTML. If these prerequisites are met, the attacker can read data exposed by the renderer, potentially including personal or confidential information.
OpenCVE Enrichment