Executive brief
Google Chrome's BackgroundFetch feature contains a confused deputy vulnerability that allows an attacker who has compromised the browser's renderer process to leak sensitive information. A user visiting a malicious website could lead to exposure of confidential data that the compromised process has access to.
Technical details
This is a confused deputy vulnerability in BackgroundFetch, a component that handles background data synchronization in Chrome. The vulnerability exists when an attacker has already compromised the renderer process and can exploit the privilege boundary between the compromised renderer and BackgroundFetch to leak sensitive information. The attack requires prior renderer process compromise and a crafted HTML page delivered to the victim. The vulnerability is fixed in Chrome 153.0.8010.36 and later versions.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched: Chrome 153.0.8010.36 released to stable channel