Impact
Google Chrome’s Workers implementation contains an authorization flaw that allows a crafted web page to load a worker from any origin, bypassing the same‑origin restriction. This flaw, identified as CWE‑863, can let a remote attacker read or modify data that would normally be protected by the browser’s origin policy, leading to potential data disclosure or unauthorized manipulation of cross‑origin resources. The impact is confined to the victim’s browser context rather than the underlying operating system or network.
Affected Systems
Any installation of Google Chrome older than version 153.0.8010.36 is vulnerable. The flaw exists across all supported platforms for Chrome, with no sub‑product or platform distinction specified in the advisory. Updating to Chrome 153.0.8010.36 or newer eliminates the vulnerability.
Risk and Exploitability
The CVSS score of 4.3 indicates medium severity, reflecting compromise of browser‑level data but no system‑wide effect. With an EPSS score of less than 1% and the vulnerability not appearing in the CISA KEV catalog, the probability of public exploitation is low at present. The likely attack vector is a remote user loading a malicious web page that crafts a worker request; therefore, most risk arises from standard web browsing exposures. The overall threat level remains moderate, but organizations should consider mitigation promptly to prevent potential data compromise.
OpenCVE Enrichment
Debian DLA
Debian DSA