Impact
An inappropriate handling of untrusted content in Google Chrome’s ServiceWorker implementation allows a malicious extension, if installed, to inject arbitrary scripts or HTML into pages that the user visits. The vulnerability is associated with CWE‑79 and is rated medium severity by Chromium. Based on the description, it is inferred that such injected scripts could deface pages, redirect users, or exfiltrate sensitive data that the page presents, although those specific exploitation outcomes are not explicitly stated in the advisory.
Affected Systems
Google Chrome installations any build earlier than 148.0.7778.96 are affected, including the stable desktop channel. All users who have default or unverified extensions installed on these builds are at risk.
Risk and Exploitability
The exploit requires social engineering to convince a user to add a malicious extension. Once installed, the extension can run scripts with the privileges of the affected browser instance. No public exploitation has been reported, the EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 5.4 reflects a medium severity level, and the risk is heightened for enterprises with unmanaged extension policies.
OpenCVE Enrichment
Debian DSA