Executive brief
Google Chrome's ServiceWorker component contains an incorrect authorization flaw that allows attackers to bypass the browser's site isolation security boundary. An attacker who has already compromised the renderer process (the component that interprets web pages) can exploit this to access data from other websites, undermining the sandbox protections that prevent malicious sites from stealing user information.
Technical details
This vulnerability is an authorization bypass in Chrome's ServiceWorker implementation that fails to properly enforce site isolation boundaries. The vulnerability requires that the attacker has already compromised the renderer process, which is typically achieved through a separate vulnerability. The attack vector is via a crafted HTML page served to the compromised renderer. An attacker who has renderer-process-level access can exploit this flaw to circumvent site isolation, potentially gaining unauthorized access to sensitive data from other websites. The vulnerability was patched in Chrome 153.0.8010.36.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched: Chrome 153.0.8010.36 released