Description
Incorrect authorization in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-09-09
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: Origin Policy Bypass
Action: Assess
AI Analysis

Impact

The vulnerability occurs in the ServiceWorker implementation of Google Chrome, where incorrect authorization checks (CWE-863) allow an attacker who has already compromised the renderer process to bypass the web origin policy. An attacker can thus execute a crafted HTML page that causes the browser to treat resources from other origins as if they belong to the same origin, potentially enabling cross‑origin data theft or injection of malicious resources. This flaw is classified as Low severity in Chromium's internal scoring.

Affected Systems

All builds of Google Chrome released before version 153.0.8010.36 are vulnerable. The vulnerability applies to the stable, beta and possibly dev channels that have not yet applied the 153.0.8010.36 patch. Users running any older stable channel should be considered at risk.

Risk and Exploitability

Because the flaw depends on the renderer process already being compromised, the likelihood of a direct, single‑step exploitation is low, and the EPSS score is <1%. The CVSS score is 3.1, reflecting low severity. Once the renderer is under attacker control, the privilege escalation to cross‑origin access is straightforward. The vulnerability is not listed in the CISA KEV catalog, indicating no known widespread exploitation yet. Nonetheless, given the potential for significant data exposure, organizations should treat the condition as a moderate to high risk in the presence of an active renderer compromise.

Generated by OpenCVE AI on September 9, 2026 at 19:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to version 153.0.8010.36 or later to receive the fix for ServiceWorker authorization checks
  • If an immediate upgrade is impractical, implement network or policy controls that block or limit ServiceWorker registration from untrusted origins until the update can be deployed
  • Monitor browser logs and network traffic for unexpected cross‑origin requests or unusual ServiceWorker activity, and investigate any anomalies promptly

Generated by OpenCVE AI on September 9, 2026 at 19:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Wed, 09 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Vendors & Products Google
Google chrome

Wed, 09 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Title Service Worker Authorization Bypass in Chrome Enabling Origin Policy Violation

Wed, 09 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Title Service Worker Authorization Bypass in Chrome Enabling Origin Policy Violation

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-863
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-09T17:08:31.343Z

Reserved: 2026-09-08T22:42:41.479Z

Link: CVE-2026-87614

cve-icon Vulnrichment

Updated: 2026-09-09T17:07:34.440Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:19.523

Modified: 2026-09-09T20:22:09.200

Link: CVE-2026-87614

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T00:00:06Z

Weaknesses