Junglewise Threat Intelligence

CVE-2026-5911: Google Chrome policy bypass in ServiceWorkers

CVE-2026-5911 · Severity: medium · CVSS 4.3 · Published 2026-04-08

Technologies: Apple macOS, Microsoft Windows, Google Chrome, Linux Kernel. Vendors: Apple, Microsoft, Google, Linux.

Executive brief

A security vulnerability in Google Chrome's ServiceWorkers component could allow a malicious website to bypass Content Security Policy (CSP) protections. CSP is a security layer that helps detect and mitigate certain types of attacks, including Cross-Site Scripting (XSS) and data injection. An attacker could exploit this by tricking a user into visiting a specially crafted webpage, potentially allowing unauthorized scripts to run or bypassing intended security restrictions on a site.

Technical details

A policy bypass vulnerability exists in the ServiceWorkers component of Google Chrome. The flaw is rooted in insufficient enforcement of Content Security Policy (CSP) protections when handling ServiceWorkers. A remote, unauthenticated attacker can exploit this by enticing a user to visit a maliciously crafted HTML page. Successful exploitation allows the attacker to bypass CSP restrictions, which could be leveraged to perform unauthorized actions or facilitate further web-based attacks. The vulnerability is addressed in Chrome version 147.0.7727.55.

Affected products

  • Google Chrome prior to 147.0.7727.55

Timeline

  • 2026-02-19: other: Reported to Chromium project
  • 2026-04-07: patched: Stable channel update released
  • 2026-04-08: disclosed: Initial advisory publication

References

Related threats