Executive brief
A security vulnerability in Google Chrome's ServiceWorker component could allow a malicious website to bypass the browser's Same Origin Policy. This policy is a fundamental security mechanism that prevents one website from reading data from another. If exploited, an attacker could potentially access sensitive information, such as login sessions or personal data, from other websites the user has open.
Technical details
A vulnerability exists in the ServiceWorker component of Google Chrome due to insufficient policy enforcement. By enticing a user to visit a specially crafted HTML page, a remote attacker can exploit this flaw to bypass the Same Origin Policy (SOP). This bypass could allow the attacker's site to interact with or retrieve data from other origins that should be isolated. The issue is addressed in Chrome version 151.0.7922.72 for Windows and Mac, and 151.0.7922.71 for Linux.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in Chrome Stable Channel Update 151.0.7922.71/.72
- 2026-07-30: disclosed: NVD publication date