Junglewise Threat Intelligence

CVE-2026-79201: Google Chrome improper access control in Workers

CVE-2026-79201 · Severity: medium · CVSS 4.3 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's Web Workers feature, which enables background processing in web applications, contained an improper access control vulnerability. A remote attacker could exploit this by crafting a malicious HTML page to bypass the browser's same-origin policy, potentially allowing unauthorized access to data from different websites or domains.

Technical details

This is an improper access control vulnerability in Chrome's Workers implementation (CVE-2026-79201). The vulnerability allows a remote attacker to bypass the web origin policy through a crafted HTML page. The attack is network-based and requires no authentication or user interaction beyond visiting a malicious webpage. The vulnerability was addressed in Chrome 152.0.7977.65 and later versions. An attacker exploiting this could access data from origins other than the attacker's origin, violating browser security boundaries.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats