Impact
The vulnerability is a type confusion flaw in the ServiceWorker component of Google Chrome, allowing a remote attacker to run arbitrary code inside the browser sandbox through flaw enables code execution without user interaction beyond visiting a malicious site, and is classified as high severity under Chromium’s security rating.
Affected Systems
Google Chrome users running any version prior to 153.0.8010.47 are impacted. No other vendors or product versions are listed for this issue.
Risk and Exploitability
With a CVSS score of 8.8, the vulnerability carries a high risk of exploitation. than 1 %, indicating a low probability of current exploit activity, and the flaw is not listed in CISA’s KEV catalog. The likely attack vector is remote: an attacker delivers a malicious HTML page that triggers the type confusion within ServiceWorker, leading to code execution inside the browser sandbox.
OpenCVE Enrichment