Executive brief
Google Chrome contains an authorization bypass vulnerability in its Workers feature that could allow an attacker to circumvent the browser's same-origin policy. An attacker who compromises the browser's rendering process and uses social engineering could trick users into visiting a malicious webpage, potentially leading to unauthorized access to data from other web origins.
Technical details
This is an authorization bypass vulnerability in the Workers implementation within Google Chrome. The vulnerability allows an attacker who has compromised the renderer process to leverage social engineering tactics to bypass the web origin policy through a crafted HTML page. The attack requires that the renderer process be compromised and necessitates user interaction via social engineering. Successful exploitation enables an attacker to circumvent the same-origin policy restrictions, potentially accessing data from unintended origins. The vulnerability was patched in Chrome version 151.0.7922.173 and later.
Affected products
- Google Chrome prior to 151.0.7922.173
Timeline
- 2026-08-20: disclosed
- 2026-08-20: patched: Fixed in Chrome 151.0.7922.173 and later