Impact
The vulnerability is an insufficient policy enforcement in the Service Worker component of Google Chrome, allowing a remote attacker to bypass the same‑origin policy through a specially crafted HTML page. This flaw enables cross‑origin access to protected resources and data, potentially leading to information disclosure or downstream exploitation. Chromium rates this issue as high severity.
Affected Systems
All Google Chrome browsers with a version prior to 148.0.7778.179 are affected.
Risk and Exploitability
The exploit requires an attacker‑controlled HTML page that a victim opens in a vulnerable Chrome instance. Because the flaw is remote and only needs a malicious page, the threat surface is wide. No EPSS data is available, and the vulnerability is not listed in CISA’s KEV catalog. The CVSS score of 4.3, combined with Chromium’s high severity rating, indicates that the potential impact is significant, especially for sites that rely heavily on Service Workers for functionality or caching.
OpenCVE Enrichment
Debian DSA