Impact
The vulnerability occurs in the ServiceWorker implementation of Google Chrome, where incorrect authorization checks (CWE-863) allow an attacker who has already compromised the renderer process to bypass the web origin policy. An attacker can thus execute a crafted HTML page that causes the browser to treat resources from other origins as if they belong to the same origin, potentially enabling cross‑origin data theft or injection of malicious resources. This flaw is classified as Low severity in Chromium's internal scoring.
Affected Systems
All builds of Google Chrome released before version 153.0.8010.36 are vulnerable. The vulnerability applies to the stable, beta and possibly dev channels that have not yet applied the 153.0.8010.36 patch. Users running any older stable channel should be considered at risk.
Risk and Exploitability
Because the flaw depends on the renderer process already being compromised, the likelihood of a direct, single‑step exploitation is low, and the EPSS score is <1%. The CVSS score is 3.1, reflecting low severity. Once the renderer is under attacker control, the privilege escalation to cross‑origin access is straightforward. The vulnerability is not listed in the CISA KEV catalog, indicating no known widespread exploitation yet. Nonetheless, given the potential for significant data exposure, organizations should treat the condition as a moderate to high risk in the presence of an active renderer compromise.
OpenCVE Enrichment
Debian DLA
Debian DSA