Junglewise Threat Intelligence

CVE-2026-79136: Google Chrome incorrect authorization in ServiceWorker

CVE-2026-79136 · Severity: medium · CVSS 4.3 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's ServiceWorker component contains an authorization flaw that allows remote attackers to bypass web origin policy protections through a crafted HTML page. This could permit an attacker on the network to access data or functionality that should be restricted to specific websites, potentially compromising user privacy and security.

Technical details

CVE-2026-79136 is an incorrect authorization vulnerability in Google Chrome's ServiceWorker implementation. The flaw allows an attacker to craft a malicious HTML page that, when accessed by a user, bypasses the browser's same-origin policy protections enforced by ServiceWorkers. An attacker can serve this page over the network, and exploitation requires user interaction (visiting the crafted page). The vulnerability enables circumvention of origin-based access controls, potentially leading to unauthorized data access or functional abuse. Google resolved this issue in Chrome 152.0.7977.65 for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats