Executive brief
A vulnerability in Google Chrome's ServiceWorker component could allow a malicious website to access data from other websites you have open. This occurs because the browser does not properly enforce security boundaries between different web origins. An attacker could exploit this by tricking a user into visiting a specially crafted webpage, potentially leading to the unauthorized disclosure of sensitive information.
Technical details
An insufficient policy enforcement vulnerability exists in the ServiceWorker component of Google Chrome. The flaw allows a remote attacker to bypass Same-Origin Policy (SOP) protections and leak cross-origin data. To exploit this, an attacker must entice a user to visit a malicious website containing a specially crafted HTML page. Successful exploitation results in the disclosure of information from other origins that should be restricted. The issue is resolved in Chrome version 149.0.7827.53 and later.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome stable channel update released.
- 2026-06-04: disclosed: CVE published in NVD.