Impact
The flaw in Google Chrome’s BackgroundFetch component is a confused deputy bug (CWE‑441). A remote attacker who first compromises the renderer process can craft an HTML page that causes BackgroundFetch to reveal sensitive information stored in the renderer’s context. The impact is the disclosure of data that the attacker should not be able to access, such as page content or credentials, once renderer privileges are obtained.
Affected Systems
Users running versions of Google Chrome before 153.0.8010.36 are affected. The issue relates solely to the browser and does not involve operating system components.
Risk and Exploitability
The vulnerability requires an attacker to have already compromised the renderer process, making the attack path more complex than a pure out‑of‑band exploit. The EPSS score is < 1%, and the CVSS score is 5.3; the vulnerability is not listed in the CISA KEV catalog. Nevertheless, because the flaw can be triggered by a crafted HTML page, a malicious website could potentially trigger the data leak if the user’s renderer process has been previously breached.
OpenCVE Enrichment
Debian DLA
Debian DSA