Executive brief
Google Chrome's Web Workers feature contains a race condition that could allow an attacker to bypass the browser's web origin security policy. An attacker would need to first compromise the renderer process (the component that executes website code), then exploit this flaw through a specially crafted webpage to potentially access resources or data from other origins that should be restricted. This could lead to unauthorized access to sensitive data or cross-site attacks.
Technical details
A race condition exists in the Web Workers implementation in Chrome prior to version 152.0.7977.65. The vulnerability allows an attacker who has already compromised the renderer process to bypass the same-origin policy through a crafted HTML page. The race condition likely occurs in the worker initialization or security validation logic, creating a window where origin checks can be bypassed if timing conditions align. This is a post-compromise vulnerability requiring an attacker to have already achieved code execution in the renderer process. The fix is available in Chrome 152.0.7977.65 and later.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Chrome 152.0.7977.65