Impact
The flaw is an inappropriate implementation of ServiceWorker in Google Chrome before version 148.0.7778.96 that permits a remote attacker who has already taken control of the renderer process to sidestep site isolation protections. Based on the description, it is inferred that the attacker must already be able to compromise the renderer process, typically through some earlier exploitation of web content or local code execution. This bypass can allow malicious content to share a renderer with trusted sites, potentially leading to cross‑site data leakage or privilege escalation.
Affected Systems
Google Chrome users running any version prior to 148.0.7778.96 are affected. The vulnerability applies to all desktop installations of Chrome that have not yet been updated to the patched version.
Risk and Exploitability
This vulnerability has a CVSS score of 3.1, indicating low severity. The EPSS score is not available, so the likelihood of exploitation is currently unknown. It is not listed in CISA’s KEV catalog, which suggests no widespread exploitation has been reported. Based on the description, it is inferred that when a renderer process is compromised, the flaw permits a site isolation bypass that could lead to cross‑site data leakage or privilege escalation. While the base score is low, the potential impact can be significant if the attacker meets the prerequisites.
OpenCVE Enrichment
Debian DSA