Impact
The vulnerability is an improper input validation in the ServiceWorker feature of Google Chrome that allows a remote attacker to bypass the browser’s system access restrictions by delivering a crafted HTML page. Chromium classified the weakness as low severity, indicating that its impact is limited under normal circumstances.
Affected Systems
All Chrome installations before version 152.0.7977.65 are affected; any user running a pre‑152.0.7977.65 build is at risk.
Risk and Exploitability
With a CVSS score of 4.3 and an EPSS score of less than 1%, the flaw is classified as low to moderate severity and is not yet listed in CISA’s KEV catalog. Exploitation requires the attacker to supply a malicious HTML page that a user visits and that triggers a ServiceWorker registration, so the attack depends on user interaction and is considered moderately unlikely but still possible. Updating to the patched version is the most reliable defense.
OpenCVE Enrichment
Debian DLA
Debian DSA