Impact
The vulnerability is a missing authorization check in the ServiceWorker implementation of Google Chrome. A remote attacker who has already gained control of the renderer process can exploit this flaw by serving a specially crafted HTML page. The exploitation bypasses system access restrictions, allowing the attacker to elevate privileges within the browser and access protected resources without proper authorization. While Chromium ranks the severity as low, the lack of a check presents a clear privilege escalation vector within the Chrome execution environment.
Affected Systems
All installations of Google Chrome running versions earlier than 153.0.8010.36 are affected, as the issue exists in all releases prior to that exact version threshold.
Risk and Exploitability
The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog. Although the renderer process compromise required for exploitation limits the attack surface, the flaw enables unauthorized access once that initial foothold is achieved. The CVSS score of 6.5 indicates moderate severity; given the privilege escalation nature and that an attacker can trigger the flaw via a crafted web page, the risk is moderate and the vulnerability still merits timely remediation.
OpenCVE Enrichment
Debian DLA
Debian DSA