Impact
An incorrect authorization check in Google Chrome’s ServiceWorker implementation, present in releases before 153.0.8010.36, permits a remote attacker who has already compromised the renderer process to bypass the browser’s site isolation mechanism by serving a crafted HTML page. This flaw is a CWE-266 and CWE-863: Incorrect Authorization, and it is rated medium severity by Chromium security, allowing the attacker to view or manipulate content that should be protected by cross‑origin boundaries.
Affected Systems
Desktop deployments of Google Chrome that are running any version earlier than 153.0.8010.36 are vulnerable. Users of those versions are susceptible unless mitigated by enterprise or individual controls.
Risk and Exploitability
The EPSS score is < 1% and the vulnerability is not listed in CISA’s KEV catalog. The CVSS score of 8.1 indicates a high severity level for this flaw. The risk requires that the attacker first gain control of the renderer process, which could be achieved through another vulnerability or social engineering. Once renderer compromise is achieved, the site isolation protection is removed, potentially exposing cross‑origin data or facilitating further escalation. Based on the current information, the overall risk to organizations using the affected Chrome versions is moderate pending mitigation.
OpenCVE Enrichment
Debian DLA
Debian DSA