Executive brief
Google Chrome's ServiceWorker component contains an information leak vulnerability that allows attackers to access sensitive cross-origin data through a malicious web page. This could result in theft of authentication tokens, session cookies, or other confidential user data from legitimate websites. The vulnerability affects Chrome versions prior to 152.0.7977.65 and has been patched in the stable release.
Technical details
The vulnerability is an information leak in Chrome's ServiceWorker component that allows a remote attacker to obtain cross-origin data via a crafted HTML page. ServiceWorkers are JavaScript workers that run in the background and can intercept network requests; the flaw permits unauthorized access to data that should be protected by same-origin policy. The attack requires only network reachability and a user to visit a crafted malicious webpage—no authentication or advanced user interaction is needed. Successful exploitation enables an attacker to exfiltrate sensitive cross-origin information. The vulnerability has been patched in Chrome 152.0.7977.65 and later versions.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65