Junglewise Threat Intelligence

CVE-2026-87439: Google Chrome information leak in ServiceWorker

CVE-2026-87439 · Severity: medium · CVSS 5.3 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's ServiceWorker component allowed a compromised renderer process to leak sensitive information through a crafted HTML page. An attacker who has already compromised the browser's rendering engine could extract data that should remain isolated, potentially exposing user information or stored credentials. This vulnerability requires prior compromise of the renderer process, limiting but not eliminating the risk.

Technical details

A information leak vulnerability exists in the ServiceWorker implementation of Google Chrome prior to version 153.0.8010.36. The vulnerability allows a remote attacker who has compromised the renderer process to obtain sensitive information by serving a specially crafted HTML page. The attack requires prior compromise of the renderer process and cannot be exploited from a fully sandboxed context. No public exploit code has been reported. The vulnerability was patched in Chrome version 153.0.8010.36.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed: CVE-2026-87439 published
  • 2026-09-08: patched: Chrome 153.0.8010.36 released with fix

References

Related threats