Impact
The vulnerability stems from an improper resource exposure in the CacheStorage feature of Google Chrome dedicated to web caching. A malicious web page can access the exposed cache, allowing the attacker to execute arbitrary code inside the browser's sandboxed environment. Chromium flags the flaw as high severity, and exploitation results in code execution with the sandbox’s privileges.
Affected Systems
Google Chrome browsers built before version 152.0.7977.82 are affected. All later releases have applied the fix. Users on the stable channel should verify that their installation is at least 152.0.7977.82.
Risk and Exploitability
The CVSS score is 8.8, indicating high severity. An attacker can trigger the vulnerability by delivering a crafted HTML page to the victim. No EPSS score is published, and the issue is not in the CISA KEV catalog, but the flaw’s high severity and the ability to execute sandboxed code suggest a non‑negligible risk to affected users.
OpenCVE Enrichment
Debian DLA
Debian DSA