Impact
A defect in the ServiceWorker implementation allows a remote attacker to expose data that should be restricted to a different origin when a specially crafted HTML page is loaded. The result is a loss of confidentiality for cross‑origin resources that the victim has access to. The weakness is classified as CWE‑200, an information exposure flaw.
Affected Systems
Google Chrome desktop versions before 152.0.7977.65 are vulnerable. If you are running one of those builds on any operating system, you may be exposed to this data‑leak condition.
Risk and Exploitability
The vulnerability is considered medium severity by Chromium, and the CVSS score is 4.3. The EPSS score is < 1%, indicating a very low likelihood of exploitation. The attack requires a malicious web page to be served to a user who runs Chrome, and the user must visit that page. Because it is not listed in the CISA KEV catalog and the EPSS score is very low, the likelihood of widespread exploitation remains low; however, if an attacker can drive victims to a malicious site, the data leakage can be leveraged for further attacks.
OpenCVE Enrichment
Debian DLA
Debian DSA