Impact
A remote attacker can trigger a crafted web page that exercises a ServiceWorker in Google Chrome, causing the browser to expose sensitive information that it should not reveal. The weakness is identified as an information‑leak vulnerability (CWE‑200) and is classified with a medium severity by the Chromium security team. If exploited, confidential data such as credentials, local file content, or cookie values could be accessed by the attacker, thereby compromising the confidentiality of the user’s data.
Affected Systems
All installations of Google Chrome on any operating system that are running a version older than 152.0.7977.65 are impacted. Users who still rely on these outdated releases are therefore exposed to the information‑leak flaw until they upgrade the browser.
Risk and Exploitability
Because the vulnerability is triggered by a web page that a user can load, the attack vector is via a malicious site sending a crafted request to a victim’s Chrome instance. The EPSS score is < 1%, indicating a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the remote nature of the flaw and its medium severity mean that attackers could target large groups of users, especially if the victim visits obscure or compromised websites. Updating to a fixed release mitigates the risk entirely.
OpenCVE Enrichment
Debian DLA
Debian DSA