Impact
A use‑after‑free flaw in Chrome’s ServiceWorker component lets a remote attacker run arbitrary code outside the normal sandbox boundaries by delivering a specially crafted HTML page. The vulnerability can be triggered from a web page and provides the attacker with the ability to execute code with the privileges of the browser process, which may lead to system compromise.
Affected Systems
The issue exists in Google Chrome for desktop versions earlier than 152.0.7977.65. Users running these versions are vulnerable.
Risk and Exploitability
The CVSS score is 9.6, but the Chromium team rated the severity as medium. Exploitation would require the victim to visit a malicious webpage, making this a client‑side attack. EPSS data is unavailable and the vulnerability is not listed in the CISA KEV catalog, indicating no confirmed widespread exploitation yet. The attack vector is inferred from the description and would be through a crafted HTML page served by an adversary.
OpenCVE Enrichment
Debian DLA
Debian DSA