Junglewise Threat Intelligence

CVE-2026-13874: Google Chrome race condition in DataTransfer

CVE-2026-13874 · Severity: info · CVSS 4.3 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's data transfer handling could allow a malicious website to access sensitive information from the browser's memory. This occurs when a user visits a specially crafted web page, potentially leading to the exposure of private data. Users should update to the latest version of Chrome to mitigate this risk.

Technical details

A race condition exists within the DataTransfer implementation of Google Chrome. By enticing a user to visit a specifically crafted HTML page, a remote attacker can exploit this timing flaw to read sensitive information from the browser's process memory. The vulnerability is triggered during data handling operations, and successful exploitation results in information disclosure without requiring administrative privileges. Google has addressed this issue in version 150.0.7871.47 and later.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched: Fixed in version 150.0.7871.47

References

Related threats