Impact
Incorrect authorization in Chrome’s ServiceWorker before 153.0.8010.36 permits a remote attacker to bypass the browser’s web‑origin policy. By serving a specially crafted HTML page, an adversary can trigger the faulty authorization logic in the ServiceWorker registration process, allowing cross‑origin data access or script execution under the victim’s context. This vulnerability is a classic authority bypass (CWE-863) but is rated low by Chromium’s internal severity due to limited exploitation scope described in the advisory.
Affected Systems
All installations of Google Chrome older than version 153.0.8010.36 are affected, as the flaw resides in the ServiceWorker implementation that is present in the stable channel of that release line. This includes desktop builds across Windows, macOS, and Linux that have not yet applied the 153.0.8010.36 patch.
Risk and Exploitability
The CVSS score of 4.3 indicates a low‑to‑moderate severity, but Chromium rates it as low internally; the EPSS score of <1% suggests a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Nevertheless, the attack vector requires an attacker to host or embed a crafted HTML page that the victim will open, after which the ServiceWorker’s flawed authorization logic is triggered to bypass origin restrictions. Because the EPSS score indicates a very low probability of exploitation and the flaw is limited to manipulated browsing contexts, the likelihood of widespread exploitation remains uncertain, but the potential impact on confidentiality and integrity warrants prompt remediation.
OpenCVE Enrichment
Debian DLA
Debian DSA