Impact
The vulnerability allows a remote attacker who has already gained control of the renderer process to extract sensitive data through a specially crafted HTML page, exposing information handled by the ServiceWorker API. This constitutes an insecure information disclosure flaw and threatens the confidentiality of user data.
Affected Systems
Google Chrome browsers prior to version 153.0.8010.36 are affected. The issue exists in the ServiceWorker implementation of these builds.
Risk and Exploitability
The attack requires an attacker to have already compromised the renderer process, making the exploitation pathway indirect and limiting the likelihood of remote compromise. The EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog, indicating no publicly known exploits at this time. The CVSS score of 5.3 and the medium Chromium security severity rating reflect the potential confidentiality impact should the renderer process be subverted.
OpenCVE Enrichment
Debian DLA
Debian DSA