CVE-2026-1504
vulnerability analysis and mitigation

Overview

CVE-2026-1504 is an inappropriate implementation vulnerability in the Background Fetch API in Google Chrome that allows a remote attacker to leak cross-origin data via a crafted HTML page. It affects Google Chrome versions prior to 144.0.7559.110 and Microsoft Edge (Chromium-based). The vulnerability was reported by security researcher Luan Herrera (@lbherrera_) on January 9, 2026, and publicly disclosed on January 27, 2026, when Google released the patched stable channel update. It carries a CVSS v3.1 base score of 6.5 (Medium), though Google rates it as High severity internally (Chrome Releases, Microsoft MSRC).

Technical details

The root cause is an inappropriate implementation in Chrome's Background Fetch API (CWE-284: Improper Access Control), which fails to properly enforce the same-origin policy when handling background fetch requests. An attacker can exploit this by hosting a crafted HTML page that leverages the Background Fetch API to initiate requests and observe responses from cross-origin resources that the victim user has access to, effectively bypassing browser isolation boundaries. Exploitation requires user interaction — specifically, the victim must visit the attacker-controlled page — but requires no special privileges or authentication. The vulnerability was tracked internally as Chromium issue 474435504 (Chrome Releases).

Impact

Successful exploitation allows an attacker to leak sensitive cross-origin data from websites the victim is authenticated to, potentially including session tokens, authentication credentials, personal information, or other confidential content. The confidentiality impact is rated High, while integrity and availability are unaffected. The attack is limited to the browser context of the victim user, but the data exposed could enable further account compromise or session hijacking on third-party sites (Chrome Releases).

Exploitation steps

  1. Reconnaissance: Identify target users who use Google Chrome versions prior to 144.0.7559.110 and are authenticated to high-value web applications (e.g., banking, email, corporate portals).
  2. Craft malicious HTML page: Create an HTML page that uses the Background Fetch API (navigator.serviceWorker and BackgroundFetchManager) to initiate fetch requests targeting cross-origin URLs that the victim is expected to have access to.
  3. Host and deliver the page: Host the malicious page on an attacker-controlled domain and lure the victim to visit it via phishing, malvertising, or a compromised website.
  4. Trigger cross-origin data leak: When the victim visits the page, the crafted JavaScript exploits the inappropriate implementation in the Background Fetch API to observe or exfiltrate response data from cross-origin resources, bypassing the same-origin policy.
  5. Exfiltrate data: Collect the leaked cross-origin data (e.g., session tokens, page content) and transmit it to an attacker-controlled server for further exploitation (Chrome Releases).

Indicators of compromise

  • Network: Unusual Background Fetch API requests originating from a browser to unexpected cross-origin domains; outbound HTTP/HTTPS requests to attacker-controlled infrastructure carrying encoded data payloads.
  • Logs: Browser or proxy logs showing Background-Fetch related service worker registrations from untrusted or unfamiliar origins; repeated cross-origin resource requests initiated without direct user navigation.
  • Process/Browser: Unexpected service worker registrations in the browser for domains not associated with known applications; JavaScript activity invoking BackgroundFetchManager APIs on pages that do not legitimately require background fetch functionality.

Mitigation and workarounds

Google has released a fix in Chrome stable channel version 144.0.7559.109/110 (Windows/Mac) and 144.0.7559.109 (Linux); users should update immediately via Chrome's built-in update mechanism (Chrome Releases). Microsoft Edge (Chromium-based) is also affected and was patched in Edge 144.0.3719.104 (Microsoft MSRC). Palo Alto Networks also released an advisory (PAN-SA-2026-0002) for Chromium-based products. As a temporary workaround prior to patching, organizations can restrict access to untrusted websites via browser security policies or web filtering, and users should avoid visiting unknown or suspicious links.

Community reactions

India's CERT-In (CERT-IN) issued a warning to macOS and Chrome users about this and related vulnerabilities, urging immediate updates to prevent data theft, which received coverage from multiple Indian technology news outlets (The Hans India). Security news outlets including CyberSecurityNews, GBHackers, SecurityOnline, and CyberPress covered the patch release, highlighting the Background Fetch API flaw as a notable high-severity fix. The Hacker News included the vulnerability in its weekly security recap. Community discussion on Bluesky and Mastodon/Infosec.exchange noted the patch but characterized exploitation risk as relatively low given the absence of public PoC code.

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management