Executive brief
Google Chrome's data handling mechanism contains a memory access vulnerability that allows attackers to read memory outside the browser's sandbox using social engineering and local access to a victim's computer. This could enable attackers to extract sensitive data from the browser's memory, including cached credentials or personal information, potentially compromising user privacy and security.
Technical details
This is an out-of-bounds read vulnerability in the DataTransfer component of Google Chrome prior to version 153.0.8010.52. The vulnerability allows a local attacker to read memory beyond allocated buffer boundaries, potentially bypassing the browser sandbox through a locally installed program. Attack requires social engineering to convince a user to interact with malicious content and local execution context. An attacker can achieve information disclosure by reading sensitive data from Chrome's memory. The vulnerability was patched in Chrome 153.0.8010.52 released on September 17, 2026.
Affected products
- Google Chrome prior to 153.0.8010.52
Timeline
- 2026-09-17: disclosed
- 2026-09-17: patched: Chrome 153.0.8010.52 released