Description
Incorrect authorization in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-09-09
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Web origin policy bypass
Action: Patch Now
AI Analysis

Impact

Incorrect authorization in Chrome’s ServiceWorker before 153.0.8010.36 permits a remote attacker to bypass the browser’s web‑origin policy. By serving a specially crafted HTML page, an adversary can trigger the faulty authorization logic in the ServiceWorker registration process, allowing cross‑origin data access or script execution under the victim’s context. This vulnerability is a classic authority bypass (CWE-863) but is rated low by Chromium’s internal severity due to limited exploitation scope described in the advisory.

Affected Systems

All installations of Google Chrome older than version 153.0.8010.36 are affected, as the flaw resides in the ServiceWorker implementation that is present in the stable channel of that release line. This includes desktop builds across Windows, macOS, and Linux that have not yet applied the 153.0.8010.36 patch.

Risk and Exploitability

The CVSS score of 4.3 indicates a low‑to‑moderate severity, but Chromium rates it as low internally; the EPSS score of <1% suggests a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Nevertheless, the attack vector requires an attacker to host or embed a crafted HTML page that the victim will open, after which the ServiceWorker’s flawed authorization logic is triggered to bypass origin restrictions. Because the EPSS score indicates a very low probability of exploitation and the flaw is limited to manipulated browsing contexts, the likelihood of widespread exploitation remains uncertain, but the potential impact on confidentiality and integrity warrants prompt remediation.

Generated by OpenCVE AI on September 9, 2026 at 20:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 153.0.8010.36 or later to receive the authorization fix for ServiceWorker.
  • Continuously monitor Chrome’s security release notes to apply the latest patches in a timely fashion.
  • For environments that cannot immediately upgrade, disable the ServiceWorker feature via Chrome policies or command‑line flags until a patched release is available.

Generated by OpenCVE AI on September 9, 2026 at 20:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Wed, 09 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Vendors & Products Google
Google chrome

Wed, 09 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}


Wed, 09 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Title Authorization Bypass in ServiceWorker Allowing Origin Policy Bypass chromium-browser: chromium-browser: Incorrect authorization in ServiceWorker
Weaknesses CWE-940
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}

threat_severity

Moderate


Wed, 09 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Title Authorization Bypass in ServiceWorker Allowing Origin Policy Bypass

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-863
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-09T17:26:45.785Z

Reserved: 2026-09-08T22:41:56.439Z

Link: CVE-2026-87598

cve-icon Vulnrichment

Updated: 2026-09-09T17:22:40.883Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:17.787

Modified: 2026-09-09T20:22:38.443

Link: CVE-2026-87598

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-09T00:10:00Z

Links: CVE-2026-87598 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T22:45:10Z

Weaknesses
  • CWE-863

    Incorrect Authorization

  • CWE-940

    Improper Verification of Source of a Communication Channel