Junglewise Threat Intelligence

CVE-2026-9116: Google Chrome insufficient policy enforcement in ServiceWorker

CVE-2026-9116 · Severity: medium · CVSS 4.3 · Published 2026-05-20

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security flaw in Google Chrome's ServiceWorker component could allow a malicious website to access data from other websites you have open. This bypasses standard browser security boundaries designed to keep information from different sites separate. An attacker could exploit this by tricking a user into visiting a specially crafted webpage, potentially leading to the exposure of sensitive personal or session data.

Technical details

A vulnerability classified as insufficient policy enforcement exists in the ServiceWorker component of Google Chrome. The flaw allows a remote attacker to bypass Same-Origin Policy (SOP) protections and leak cross-origin data. To exploit the vulnerability, an attacker must entice a user to visit a malicious HTML page. The root cause is a failure in the ServiceWorker's mechanism for enforcing security boundaries between different origins. This issue is resolved in Chrome version 148.0.7778.179 for Mac and Windows, and 148.0.7778.178 for Linux.

Affected products

  • Google Chrome prior to 148.0.7778.179

Timeline

  • 2026-03-29: disclosed: Reported to Chromium project by Google researchers
  • 2026-05-19: patched: Stable channel update released for desktop
  • 2026-05-20: advisory: NVD publication date

References

Related threats