Junglewise Threat Intelligence

CVE-2026-91709: Google Chrome type confusion in ServiceWorker

CVE-2026-91709 · Severity: high · CVSS 8.8 · Published 2026-09-15

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's ServiceWorker component contains a type confusion vulnerability that allows remote attackers to execute arbitrary code within the browser's sandbox. An attacker can exploit this by hosting a specially crafted HTML page, potentially compromising user data, session credentials, or enabling further system exploitation without requiring any user interaction beyond visiting the malicious site.

Technical details

The vulnerability is a type confusion flaw in the ServiceWorker component of Google Chrome, which handles background tasks and offline functionality. The vulnerability exists in Chrome versions prior to 153.0.8010.47 and requires no user authentication or local access. An attacker can craft a malicious HTML page that triggers the type confusion, leading to arbitrary code execution within the Chrome sandbox. The sandbox confinement limits direct system-wide impact, but code execution within the browser process allows theft of sensitive data and potential escape exploits. Patches are available in Chrome 153.0.8010.47 and later.

Affected products

  • Google Chrome prior to 153.0.8010.47

Timeline

  • 2026-09-15: disclosed: CVE-2026-91709 published

References

Related threats