Impact
This issue is a type confusion vulnerability in the ServiceWorker component of Google Chrome that enables an attacker to run arbitrary code inside the browser sandbox by loading a specially crafted webpage. The flaw allows code execution without any user interaction beyond visiting the malicious site, and it is rated as high severity under Chromium’s internal security assessment.
Affected Systems
All users of Google Chrome whose browsers are running versions prior to 153.0.8010.47 are impacted. No other vendors or product versions appear to be affected by this flaw.
Risk and Exploitability
With a CVSS score of 8.8 the vulnerability poses a high risk of exploitation. The EPSS score of less than 1 % indicates that, at present, the likelihood of exploited activity is low, and the flaw is not listed in CISA’s KEV catalog. The most likely attack vector is remote: an adversary delivers a malicious HTML page that exploits type confusion within ServiceWorker, leading to code execution inside the sandbox.
OpenCVE Enrichment
Debian DLA
Debian DSA