Executive brief
Google Chrome's ServiceWorker component contains an information leak vulnerability that allows attackers to extract sensitive data by tricking users into visiting a malicious webpage. This could expose user credentials, browsing data, or other confidential information stored within the browser. The vulnerability affects all versions of Chrome prior to 152.0.7977.65 on Windows, Mac, and Linux.
Technical details
The vulnerability is an information leak in Chrome's ServiceWorker implementation that can be exploited via a crafted HTML page. ServiceWorkers are background scripts that enable offline functionality and caching; the flaw allows remote attackers to access sensitive data they should not have access to without requiring authentication or special user interaction beyond visiting a malicious page. The attack vector is network-based and affects Chrome versions before 152.0.7977.65. Google has patched this vulnerability in the Chrome 152 stable release (152.0.7977.64/65 for Linux and Windows/Mac respectively).
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.64/65