Executive brief
A security vulnerability in Google Chrome's ServiceWorkers component could allow a malicious website to bypass Content Security Policy (CSP) protections. CSP is a security layer that helps detect and mitigate certain types of attacks, including Cross-Site Scripting (XSS) and data injection. An attacker could exploit this by tricking a user into visiting a specially crafted webpage, potentially allowing unauthorized scripts to run or bypassing intended security restrictions on a site.
Technical details
A policy bypass vulnerability exists in the ServiceWorkers component of Google Chrome. The flaw is rooted in insufficient enforcement of Content Security Policy (CSP) protections when handling ServiceWorkers. A remote, unauthenticated attacker can exploit this by enticing a user to visit a maliciously crafted HTML page. Successful exploitation allows the attacker to bypass CSP restrictions, which could be leveraged to perform unauthorized actions or facilitate further web-based attacks. The vulnerability is addressed in Chrome version 147.0.7727.55.
Affected products
- Google Chrome prior to 147.0.7727.55
Timeline
- 2026-02-19: other: Reported to Chromium project
- 2026-04-07: patched: Stable channel update released
- 2026-04-08: disclosed: Initial advisory publication