Insufficient Policy Enforcement in Service Worker of Google Chrome
CVE-2026-9115

4.3MEDIUM

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
20 May 2026

What is CVE-2026-9115?

A critical vulnerability exists in the Service Worker component of Google Chrome that allows attackers to circumvent the same origin policy by exploiting insufficient policy enforcement. By leveraging a specially crafted HTML page, an unauthorized remote attacker can interact with resources from a different origin, potentially leading to exposure of sensitive data or unauthorized actions. This vulnerability highlights the importance of robust security measures in web applications to protect against such attacks.

Affected Version(s)

Chrome 148.0.7778.179

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.