Impact
The vulnerability is a use-after-free bug in the ServiceWorker implementation of Google Chrome. The flaw allows a malicious web page to reference freed memory, potentially enabling execution of arbitrary code outside the browser sandbox. This type of defect is captured by CWE-416 and can compromise confidentiality, integrity, and availability if successfully exploited.
Affected Systems
All users running Google Chrome versions earlier than 152.0.7977.65 are affected. The issue was reported for Chrome prior to the 152.0.7977.65 release and is fixed in that update and later releases.
Risk and Exploitability
Chromium lists the defect as High severity with a CVSS score of 9.6, and no exploit has been publicly documented. The EPSS score is unavailable, and the vulnerability is not in the CISA KEV catalog, indicating limited observed exploitation. Nonetheless, a crafted HTML page delivered by a remote website can trigger the use-after-free with only standard activity, making the attack feasible from the user’s machine.
OpenCVE Enrichment
Debian DLA
Debian DSA