Junglewise Threat Intelligence

CVE-2026-87614: Google Chrome incorrect authorization in ServiceWorker

CVE-2026-87614 · Severity: low · CVSS 3.1 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's ServiceWorker component had an authorization flaw that could allow an attacker who compromised the browser's rendering engine to bypass web origin security policies. This could enable unauthorized access to content from other websites or permit malicious actions on behalf of the user.

Technical details

This vulnerability is an authorization bypass in Chrome's ServiceWorker implementation. An attacker who has already achieved renderer process compromise can craft a malicious HTML page to bypass the same-origin policy (SOP) and web origin restrictions. The attack requires prior compromise of the renderer process and user interaction to load a crafted webpage. The vulnerability was patched in Chrome 153.0.8010.36 released on September 8, 2026.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched

References

Related threats