Impact
A race condition in PlatformIntegration of Google Chrome on macOS before version 153.0.8010.47 allows a remote attacker who has already compromised the renderer process to deliver a crafted HTML page that can read data the renderer can access, leading to leakage of potentially personal or confidential information. The flaw is a concurrency control failure and is identified as CWE-367 and CWE-368, which Chromium rates as high severity.
Affected Systems
The vulnerability affects Google Chrome running on macOS versions earlier than 153.0.8010.47; other operating systems and newer Chrome releases are not impacted.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate base severity, but Chromium's high rating reflects the serious confidentiality impact. The EPSS score of less than 1% shows a low probability of exploit in the wild, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires prior compromise of the renderer process—likely via another flaw or malicious content—and then a social engineering attack that serves the malicious HTML to trigger the race condition. If these conditions are met, the attacker can read sensitive data exposed by the renderer.
OpenCVE Enrichment
Debian DLA
Debian DSA