Description
Inappropriate implementation in Workers in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-06-04
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An inappropriate implementation in the Web Workers component of Google Chrome prior to version 149.0.7827.53 allows an attacker who can serve a specially crafted HTML page to the browser to bypass the same‑origin policy. The flaw permits reading or interacting with data from other origins that should be inaccessible, potentially leading to data theft, credential leakage, or facilitation of further client‑side attacks. The flaw is identified as a medium severity issue within Chromium's own scoring system.

Affected Systems

Users with Google Chrome versions older than 149.0.7827.53 are affected. The CVE does not specify the operating system or platform, so that information is not documented; it is inferred that the issue applies to desktop Chrome installations, but the CVE does not explicitly state that. The vulnerability targets the Workers API used for background script execution in the browser and covers all releases in the stable channel before the patched version.

Risk and Exploitability

The CVSS score is 6.5, indicating medium severity, while the EPSS score is < 1%, implying low exploitation probability. The issue is not listed in CISA’s KEV catalog. A common attack vector is a malicious web page that the attacker controls; by embedding a worker that accesses cross‑origin resources, an attacker could read sensitive data. No known public exploit is documented, but the vulnerability requires the victim to visit a crafted page and has no additional host‑side prerequisites.

Generated by OpenCVE AI on June 7, 2026 at 13:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 149.0.7827.53 or later to apply the vendor’s fix.
  • Enable automatic updates for Chrome so that future security patches are applied without manual intervention.
  • Where possible, employ strict Content Security Policy headers to restrict or disable the use of Workers from untrusted origins until the patch is available.

Generated by OpenCVE AI on June 7, 2026 at 13:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6325-1 chromium security update
History

Mon, 08 Jun 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 07 Jun 2026 12:15:00 +0000

Type Values Removed Values Added
Title chromium-browser: Inappropriate implementation in Workers
Weaknesses CWE-346
References
Metrics threat_severity

None

threat_severity

Moderate


Sat, 06 Jun 2026 04:15:00 +0000

Type Values Removed Values Added
Title Same-Origin Policy Bypass via Web Workers in Google Chrome
Weaknesses CWE-200
CWE-285

Sat, 06 Jun 2026 02:00:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}


Fri, 05 Jun 2026 03:30:00 +0000

Type Values Removed Values Added
Title Same-Origin Policy Bypass via Web Workers in Google Chrome
Weaknesses CWE-200
CWE-285

Fri, 05 Jun 2026 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 04 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in Workers in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-06-08T16:32:39.808Z

Reserved: 2026-06-04T17:06:25.061Z

Link: CVE-2026-10996

cve-icon Vulnrichment

Updated: 2026-06-08T16:31:48.445Z

cve-icon NVD

Status : Modified

Published: 2026-06-04T23:17:03.250

Modified: 2026-06-08T17:16:34.293

Link: CVE-2026-10996

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-06-02T00:00:00Z

Links: CVE-2026-10996 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-06-07T14:00:09Z

Weaknesses