
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-1504 is an inappropriate implementation vulnerability in the Background Fetch API in Google Chrome that allows a remote attacker to leak cross-origin data via a crafted HTML page. It affects Google Chrome versions prior to 144.0.7559.110 and Microsoft Edge (Chromium-based). The vulnerability was reported by security researcher Luan Herrera (@lbherrera_) on January 9, 2026, and publicly disclosed on January 27, 2026, when Google released the patched stable channel update. It carries a CVSS v3.1 base score of 6.5 (Medium), though Google rates it as High severity internally (Chrome Releases, Microsoft MSRC).
The root cause is an inappropriate implementation in Chrome's Background Fetch API (CWE-284: Improper Access Control), which fails to properly enforce the same-origin policy when handling background fetch requests. An attacker can exploit this by hosting a crafted HTML page that leverages the Background Fetch API to initiate requests and observe responses from cross-origin resources that the victim user has access to, effectively bypassing browser isolation boundaries. Exploitation requires user interaction — specifically, the victim must visit the attacker-controlled page — but requires no special privileges or authentication. The vulnerability was tracked internally as Chromium issue 474435504 (Chrome Releases).
Successful exploitation allows an attacker to leak sensitive cross-origin data from websites the victim is authenticated to, potentially including session tokens, authentication credentials, personal information, or other confidential content. The confidentiality impact is rated High, while integrity and availability are unaffected. The attack is limited to the browser context of the victim user, but the data exposed could enable further account compromise or session hijacking on third-party sites (Chrome Releases).
navigator.serviceWorker and BackgroundFetchManager) to initiate fetch requests targeting cross-origin URLs that the victim is expected to have access to.Background-Fetch related service worker registrations from untrusted or unfamiliar origins; repeated cross-origin resource requests initiated without direct user navigation.BackgroundFetchManager APIs on pages that do not legitimately require background fetch functionality.Google has released a fix in Chrome stable channel version 144.0.7559.109/110 (Windows/Mac) and 144.0.7559.109 (Linux); users should update immediately via Chrome's built-in update mechanism (Chrome Releases). Microsoft Edge (Chromium-based) is also affected and was patched in Edge 144.0.3719.104 (Microsoft MSRC). Palo Alto Networks also released an advisory (PAN-SA-2026-0002) for Chromium-based products. As a temporary workaround prior to patching, organizations can restrict access to untrusted websites via browser security policies or web filtering, and users should avoid visiting unknown or suspicious links.
India's CERT-In (CERT-IN) issued a warning to macOS and Chrome users about this and related vulnerabilities, urging immediate updates to prevent data theft, which received coverage from multiple Indian technology news outlets (The Hans India). Security news outlets including CyberSecurityNews, GBHackers, SecurityOnline, and CyberPress covered the patch release, highlighting the Background Fetch API flaw as a notable high-severity fix. The Hacker News included the vulnerability in its weekly security recap. Community discussion on Bluesky and Mastodon/Infosec.exchange noted the patch but characterized exploitation risk as relatively low given the absence of public PoC code.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."