Junglewise Threat Intelligence

CVE-2026-87574: Google Chrome ServiceWorker information leak

CVE-2026-87574 · Severity: medium · CVSS 4.3 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's ServiceWorker component contained a flaw that allowed attackers to access sensitive data from other websites through a specially crafted HTML page. This could expose user information across different web origins, compromising privacy and potentially leading to unauthorized access to account data or sensitive information stored in web applications.

Technical details

This is an information disclosure vulnerability in Chrome's ServiceWorker implementation that violates same-origin policy protections. An attacker can craft a malicious HTML page that, when visited, exploits the ServiceWorker flaw to read cross-origin data that should normally be inaccessible. The vulnerability requires user interaction (visiting the crafted page) and network access. The attack succeeds against any website the user has visited or has open in another tab. The vulnerability was patched in Chrome 153.0.8010.36 released September 8, 2026.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched

References

Related threats