Junglewise Threat Intelligence

CVE-2026-79015: Google Chrome ServiceWorker input validation bypass

CVE-2026-79015 · Severity: medium · CVSS 4.3 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's ServiceWorker feature contains improper input validation that allows a remote attacker to bypass system access restrictions by sending a crafted HTML page. This could enable an attacker to execute code or access resources on a user's system that should be protected. Patching to Chrome 152 or later resolves the issue.

Technical details

The vulnerability is an improper input validation flaw in Chrome's ServiceWorker implementation (CVE-2026-79015). An unauthenticated remote attacker can exploit this via a crafted HTML page delivered over the network, bypassing system access restrictions without user interaction beyond visiting a malicious web page. The vulnerability allows circumvention of security boundaries that are normally enforced by the browser's sandbox model. Google has addressed this issue in Chrome 152.0.7977.65 and later versions.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Chrome 152.0.7977.65 and later

References

Related threats