Description
Inappropriate implementation in Workers in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-06-04
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An inappropriate implementation in the Web Workers component of Google Chrome prior to version 149.0.7827.53 allows an attacker who can serve a specially crafted HTML page to the browser to bypass the same‑origin policy. The flaw permits reading or interacting with data from other origins that should be inaccessible, potentially leading to data theft, credential leakage, or facilitation of further client‑side attacks. The flaw is identified as a medium severity issue within Chromium's own scoring system.

Affected Systems

Users with Google Chrome versions older than 149.0.7827.53 are affected. The CVE does not specify the operating system or platform, so that information is not documented; it is inferred that the issue applies to desktop Chrome installations, but the CVE does not explicitly state that. The vulnerability targets the Workers API used for background script execution in the browser and covers all releases in the stable channel before the patched version.

Risk and Exploitability

The CVSS score is not publicly available, but the reported Chromium severity is medium and the EPSS score is not disclosed, indicating low to medium exploitation probability. The issue is not listed in CISA’s KEV catalog. A common attack vector is a malicious web page that the attacker controls; by embedding a worker that accesses cross‑origin resources, an attacker could read sensitive data. No known public exploit is documented, but the vulnerability requires the victim to visit a crafted page and has no additional host‑side prerequisites.

Generated by OpenCVE AI on June 5, 2026 at 03:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 149.0.7827.53 or later to apply the vendor’s fix.
  • Enable automatic updates for Chrome so that future security patches are applied without manual intervention.
  • Where possible, employ strict Content Security Policy headers to restrict or disable the use of Workers from untrusted origins until the patch is available.

Generated by OpenCVE AI on June 5, 2026 at 03:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 05 Jun 2026 03:30:00 +0000

Type Values Removed Values Added
Title Same-Origin Policy Bypass via Web Workers in Google Chrome
Weaknesses CWE-200
CWE-285

Fri, 05 Jun 2026 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 04 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in Workers in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-06-04T23:04:13.197Z

Reserved: 2026-06-04T17:06:25.061Z

Link: CVE-2026-10996

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-06-04T23:17:03.250

Modified: 2026-06-04T23:17:03.250

Link: CVE-2026-10996

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-05T03:15:16Z

Weaknesses