Junglewise Threat Intelligence

CVE-2026-87523: Google Chrome race condition in DataTransfer

CVE-2026-87523 · Severity: medium · CVSS 5.3 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome contains a race condition vulnerability in its DataTransfer functionality that could allow attackers to trick users into visiting a malicious webpage to steal sensitive information. The vulnerability affects millions of Chrome users and requires social engineering to exploit, making it a realistic threat in phishing and credential theft attacks.

Technical details

A race condition exists in the DataTransfer component of Google Chrome prior to version 153.0.8010.36. The vulnerability allows a remote attacker to exploit a timing-dependent condition through a crafted HTML page delivered via social engineering (phishing or other user manipulation). The race condition can be triggered when a user interacts with the malicious page, leading to disclosure of sensitive information. The vulnerability has been patched in Chrome 153.0.8010.36 and later versions.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Fixed in Chrome 153.0.8010.36

References

Related threats