Executive brief
Google Chrome on macOS contains a race condition in the PlatformIntegration component that could allow an attacker who has compromised the renderer process to obtain sensitive information through social engineering. This vulnerability requires the attacker to first breach the renderer process and then trick the user into viewing a malicious HTML page, potentially exposing confidential data stored or processed by the browser.
Technical details
A race condition exists in the PlatformIntegration component of Google Chrome running on macOS prior to version 153.0.8010.47. The vulnerability is triggered when a remote attacker has already compromised the renderer process and leverages social engineering to deliver a crafted HTML page to the victim. The race condition allows the attacker to obtain sensitive information that would normally be protected. The vulnerability has been assigned Chromium security severity: High and requires both renderer compromise and user interaction. A patch is available in Chrome version 153.0.8010.47 and later.
Affected products
- Google Chrome prior to 153.0.8010.47 on macOS
Timeline
- 2026-09-15: disclosed