Impact
The flaw is a type confusion bug in the ServiceWorker component of Google Chrome that permits a maliciously crafted web page to run arbitrary code inside the browser sandbox. This weakness causes the browser to misinterpret the target type of data, leading to execution of code that the user did not intend to run. The impact is a full compromise of confidentiality, integrity, and availability for the affected Chrome instance, allowing an attacker to execute any code within the sandboxed environment.
Affected Systems
Google Chrome on desktop platforms is affected when the browser version is earlier than 153.0.8010.47. All users running these or older releases should consider themselves at risk, as the vulnerability is present across all builds that include the vulnerable ServiceWorker implementation.
Risk and Exploitability
The CVSS score of 8.8 marks this as a high severity issue. The low EPSS score of < 1% indicates that widespread exploitation has not yet been observed, and the vulnerability is not listed in The likely attack vector is remote via a crafted HTML page, where an attacker controls the page that the victim visits or injects content into a page they already view. The required conditions are minimal: the victim must visit the malicious or compromised web page while running an affected version of Chrome.
OpenCVE Enrichment