Impact
An incorrect authorization check in ServiceWorker registration logic allows a remote attacker to construct a crafted HTML page that causes the browser to register a ServiceWorker for a different origin. The flaw effectively bypasses the web origin policy, granting the attacker control over cross‑origin service workers. This weakness is classified as CWE‑863, representing a missing authorization check. The impact is a severe loss of origin isolation, allowing attackers to read or modify data from protected websites, inject malicious scripts, and potentially hijack user sessions.
Affected Systems
Google Chrome browsers on desktop platforms running any version prior to 152.0.7977.65 are susceptible. The issue has been fixed in Chrome version 152.0.7977.65 and later releases.
Risk and Exploitability
Chromium classifies this defect as medium severity, with a CVSS score of 4.3. The EPSS score is < 1%, indicating a very low exploitation probability. The vulnerability is not listed in CISA's KEV catalog. Based on the description, it is inferred that the flaw operates without requiring privileged local access, so elevated privileges are not necessary for exploitation. The likely attack vector is that a remote attacker can trigger the flaw by hosting a specially crafted HTML page and tricking a user into visiting it, or via a compromised web page that can execute scripts in the victim’s context. This implies that the vulnerability can be exploited in typical browsing scenarios, underscoring the importance of keeping Chrome updated.
OpenCVE Enrichment
Debian DLA
Debian DSA