Impact
A vulnerability exists in ServiceWorker handling in Google Chrome versions prior to 153.0.8010.36 that permits an attacker to read data from other origins when a crafted HTML page is served. The flaw violates user privacy by exposing confidential information that would otherwise be protected by the same-origin policy. It is classified as a medium-severity issue within Chromium’s security ranking.
Affected Systems
Any desktop installation of Google Chrome with a version older than 153.0.8010.36 is susceptible. The ServiceWorker feature, active in most modern Chrome deployments, is the vector through which the information leak occurs.
Risk and Exploitability
The vulnerability can be triggered remotely from a crafted HTML page, allowing the attacker to bypass same-origin restrictions and read data from other domains. While the flaw does not enable arbitrary code execution or privilege escalation, the ability to exfiltrate cross-origin data represents a significant privacy breach. The CVSS score of 4.3 indicates medium severity. The EPSS score of less than 1% suggests a low exploitation probability, though the issue is not listed in CISA KEV. Users should assess the risk of cross-origin data leakage when running older Chrome versions.
OpenCVE Enrichment
Debian DLA
Debian DSA