Executive brief
Google Chrome's ServiceWorker feature failed to properly verify authorization, allowing an attacker with a compromised renderer process to bypass system access restrictions. This could enable unauthorized access to sensitive functionality or data that should be protected by browser security boundaries.
Technical details
A missing authorization check in the ServiceWorker implementation allowed an attacker with a compromised renderer process to bypass system access restrictions via a crafted HTML page. The vulnerability exists in versions prior to 153.0.8010.36. The attack requires prior compromise of the renderer process, which could be achieved through other browser exploits. An attacker could potentially escalate privileges or access restricted resources. The fix is available in Chrome 153.0.8010.36 and later.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched