Executive brief
Google Chrome contains a race condition vulnerability in its DataTransfer functionality that could allow attackers to trick users into visiting a malicious webpage to steal sensitive information. The vulnerability affects millions of Chrome users and requires social engineering to exploit, making it a realistic threat in phishing and credential theft attacks.
Technical details
A race condition exists in the DataTransfer component of Google Chrome prior to version 153.0.8010.36. The vulnerability allows a remote attacker to exploit a timing-dependent condition through a crafted HTML page delivered via social engineering (phishing or other user manipulation). The race condition can be triggered when a user interacts with the malicious page, leading to disclosure of sensitive information. The vulnerability has been patched in Chrome 153.0.8010.36 and later versions.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched: Fixed in Chrome 153.0.8010.36