Junglewise Threat Intelligence

CVE-2026-10996: Google Chrome Same Origin Policy bypass in Workers

CVE-2026-10996 · Severity: info · CVSS 4.3 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability in Google Chrome's Web Workers implementation could allow a malicious website to bypass the Same-Origin Policy. This policy is a fundamental security boundary that prevents websites from accessing data belonging to other sites. If exploited, an attacker could potentially read or interact with sensitive information from other websites you have open in your browser.

Technical details

An inappropriate implementation in the Workers component of Google Chrome allowed a remote attacker to bypass the Same-Origin Policy (SOP). By enticing a user to visit a specially crafted HTML page, an attacker could leverage Web Workers to access data across origin boundaries. This vulnerability is categorized by Chromium as Medium severity. The issue is resolved in Google Chrome version 149.0.7827.53 and later.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
  • 2026-06-04: disclosed: CVE published

References

Related threats