
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-76019 is an incorrect authorization vulnerability in the Workers component of Google Chrome that allows a remote attacker who has compromised the renderer process to bypass web origin policy via a crafted HTML page. The vulnerability was reported anonymously on 2026-07-26 and publicly disclosed on 2026-08-20 alongside a patch. It affects all versions of Google Chrome prior to 151.0.7922.173. The Chromium security team rates this as High severity; a formal CVSS score has not yet been published (base score listed as 0.0 in ENISA data) (Chrome Releases, GitHub Advisory).
The root cause is classified as CWE-863 (Incorrect Authorization): the Workers subsystem in Chrome does not correctly enforce authorization checks, allowing the web origin policy to be circumvented. Exploitation requires two preconditions — the attacker must have already compromised the renderer process (e.g., via a separate browser vulnerability) and must also leverage social engineering to induce the victim to interact with a crafted HTML page. The crafted page exploits the flawed authorization logic in Workers to cross origin boundaries that should be enforced by the browser's same-origin policy. The Chromium issue tracker entry is tracked under issue 539032888, though full technical details remain restricted pending broad user uptake of the patch (Chrome Releases, GitHub Advisory).
Successful exploitation allows an attacker who has already compromised the renderer process to bypass Chrome's web origin policy, potentially enabling cross-origin data access, exfiltration of sensitive content from other origins, and circumvention of isolation boundaries enforced by the browser. Because exploitation requires a pre-compromised renderer, this vulnerability is most dangerous as a second-stage component in a chained attack — for example, combined with a renderer exploit to achieve a more complete browser sandbox escape or cross-site data theft (GitHub Advisory, Chrome Releases).
As of the disclosure date, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The EPSS score is 0.0, reflecting low current exploitation probability, and the vulnerability does not appear in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires chaining with a separate renderer compromise and social engineering, raising the bar for attackers significantly. Nessus detection plugins 338406 and 338407 are available for identifying unpatched systems (Tenable).
Google has released a patch in Chrome stable channel version 151.0.7922.173 (Linux) and 151.0.7922.173/.174 (Windows and Mac), rolling out as of 2026-08-20. Users and administrators should update Google Chrome to version 151.0.7922.173 or later immediately. As a defense-in-depth measure, organizations should educate users to avoid interacting with unsolicited or unfamiliar web pages, implement Content Security Policies (CSP) and strict origin restrictions on web applications, and use enterprise browser management tools to enforce timely updates (Chrome Releases, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."