Impact
Google Chrome versions older than 152.0.7977.65 contain an improper access control flaw in the implementation of Web Workers. An attacker can craft a malicious HTML page that, when opened in the victim’s browser, triggers the Workers API and bypasses the browser’s web origin policy. The result is that a page from one origin can gain unauthorized access to resources, cookies, or data belonging to another origin, allowing data theft, content injection, or unauthorized manipulation within the user’s browsing session.
Affected Systems
The vulnerability affects Google Chrome for desktop users running any build prior to version 152.0.7977.65. The flaw is specific to the Workers implementation in the stable channel and is not present in later releases.
Risk and Exploitability
The flaw is classified as medium severity by Chromium. The CVSS score is 4.3 and the EPSS score is < 1%. The attack requires a user to load a specially crafted web page, and no public exploit code or known real‑world incidents have been reported. The vulnerability is also not listed in the CISA KEV catalog. Given the widespread use of Chrome, the risk is moderate; a determined attacker could distribute malicious content that takes advantage of the flaw but the likelihood of an exploit in the wild remains uncertain without further evidence.
OpenCVE Enrichment
Debian DLA
Debian DSA