Executive brief
Google Chrome contains a flaw in its ServiceWorker authorization system that allows an attacker to bypass web origin policies. An attacker can craft a malicious HTML page that, when visited, bypasses security restrictions designed to prevent cross-origin attacks. This could allow attackers to access sensitive data or perform actions on behalf of users visiting compromised websites.
Technical details
The vulnerability is an incorrect authorization flaw in ServiceWorker handling within Google Chrome prior to version 153.0.8010.36. A remote attacker can craft a malicious HTML page to bypass the same-origin policy (SOP) and web origin restrictions enforced by ServiceWorkers. The attack requires user interaction (visiting the malicious page) and is network-based. Successful exploitation allows an attacker to circumvent origin isolation protections. The vulnerability is patched in Chrome 153.0.8010.36 and later.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched: Chrome 153.0.8010.36 released to stable channel