Impact
The vulnerability is an incorrect authorization in ServiceWorker that allows a maliciously crafted Chrome extension to bypass the web origin policy, effectively letting it read or modify data served by any origin on which the user visits. This flaw is present before Chrome version 152.0.7977.65 and enables an attacker to override same‑origin restrictions, which could lead to data theft, privacy compromise, or injection of malicious content into legitimate sites.
Affected Systems
All users of Google Chrome running any build earlier than version 152.0.7977.65 are affected. The CVE data does not indicate a specific channel or operating system.
Risk and Exploitability
The Chrome security team assigned the flaw a medium severity, reflected in a CVSS score of 4.3. The EPSS score is < 1 %, indicating a very low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a social‑engineering attack that delivers a malicious Chrome extension; once installed the extension can unconditionally bypass origin restrictions without further network interaction.
OpenCVE Enrichment
Debian DLA
Debian DSA