Impact
An improper input validation flaw in the Workers component of Google Chrome allows maliciously crafted HTML to bypass system access restrictions once the renderer process has been compromised. The flaw exploits an input validation weakness (CWE-20) and can lead to unauthorized access to system resources, elevating attacker privileges on the host machine.
Affected Systems
All users running Google Chrome older than version 152.0.7977.65 on any supported operating system are potentially affected, regardless of the browsing context.
Risk and Exploitability
Chromium rates this issue as medium severity with a CVSS score of 4.2. The EPSS score is < 1% and it is not listed in the CISA KEV catalog. Exploitation requires a remote attacker who can deliver a crafted HTML page and has already compromised the renderer process. Once inside that environment, the attacker can provide inputs that cause the Workers module to bypass system‑level access checks. The overall risk depends on the difficulty of achieving an initial renderer compromise, but if successful, the impact is significant.
OpenCVE Enrichment
Debian DLA
Debian DSA