Impact
The vulnerability is in Chrome’s CacheStorage API that permits a remote attacker to execute arbitrary code inside the browser sandbox when a victim loads a specifically crafted HTML page.
Affected Systems
All versions of Google Chrome prior to 153.0.8010.47 are impacted, regardless of operating system.
Risk and Exploitability
With a CVSS score of 8.8 the issue is categorized as high severity, yet the EPSS score of less than 1% indicates a low probability of widespread exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a remote attacker delivering a maliciously crafted web page that the victim must open; no local privilege escalation or credential compromise is required.
OpenCVE Enrichment