CVE-2026-1504Patch(google / chrome)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch google chrome systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Inappropriate implementation in Background Fetch API in Google Chrome prior to 144.0.7559.110 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

0.5/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome

Threat summary

  • Patch or workaround signal is available
  • 15 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 10 signals
  • Technical details provided in 12 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked 4d ago at 8 mentions (2026-01-28); latest day: 1
  • 15 total mentions across 6 days

Affected systems

Vendors
Products
chrome

Deep dive

Activity timeline15 mentions / 6d
02468Mentions · 2026-01-27: 1Mentions · 2026-01-28: 8Mentions · 2026-01-29: 1Mentions · 2026-01-30: 3Mentions · 2026-02-04: 1Mentions · 2026-05-21: 1Patch / Workaround · 2026-01-28: 6Patch / Workaround · 2026-01-29: 1Patch / Workaround · 2026-01-30: 2Patch / Workaround · 2026-02-04: 1Technical Details · 2026-01-27: 1Technical Details · 2026-01-28: 6Technical Details · 2026-01-29: 1Technical Details · 2026-01-30: 2Technical Details · 2026-02-04: 1Technical Details · 2026-05-21: 101-2701-2801-2901-3002-0405-21
Signal classification3 categories
Patch
960.0%
Disclosure
533.3%
General
16.7%
Referenced assets15 URLs
Classification over time
DateTotalLabels
2026-01-271
Disclosure1
2026-01-288
Disclosure1General1Patch6
2026-01-291
Disclosure1
2026-01-303
Disclosure1Patch2
2026-02-041
Patch1
2026-05-211
Disclosure1
Full discourse15 posts
  • kokumօtօ@__kokumoto
    Patch

    Chrome 144安定版にセキュリティ更新が配信。Background Fetch APIにおける不適切な実装CVE-2026-1504を修正。報奨金3千ドル。脆弱性の詳細はいつもの通り未開示。 https://securityonline.info/chrome-patches-high-severity-background-fetch-flaw-cve-2026-1504/

    Post summary

    A security patch for Chrome 144 fixes CVE-2026-1504, with no disclosed technical details, PoC, or evidence of active exploitation. No false‑positive claim is present.

    030601.0K
    7.2K followersView on X
  • コッド(データエンジニアリング)@DataEngComm
    Patch

    Google Chromeに深刻度「高」の脆弱性(CVE-2026-1504)が見つかりました。 バックグラウンドフェッチAPIの不具合が原因で、デスクトップ版・Android版が影響を受けます。 修正版が公開されているため、手動アップデートを推奨されています。 https://news.yahoo.co.jp/articles/b8fec3d2f7c221494583601e1637f3f660d34c7d

    Post summary

    A high‑severity Chrome vulnerability (CVE‑2026‑1504) affecting Desktop and Android was disclosed, and Google has released a patch, with manual updates recommended.

    021211.0K
    379 followersView on X
  • iototsecnews@iototsecnews
    Patch

    Chrome の脆弱性 CVE-2026-1504 が FIX:Background Fetch API の欠陥を修正 https://iototsecnews.jp/2026/01/28/chrome-security-update-fixes-critical-vulnerability-in-background-fetch-api/ Google Chrome に存在する、深刻な脆弱性 CVE-2026-1504 を修正する緊急アップデートが公開されました。この問題の原因は、大容量ファイルのダウンロードを、ブラウザのタブを閉じた後も継続させる Background Fetch API の不適切な実装にあります。 この脆弱性は、セキュリティ研究者の Luan Herrera により報告され、深刻度は High (高) と評価されています。悪用を防ぐために、現時点では詳細な攻撃手法が非公開とされていますが、Background Fetch API の実装ミスを突かれることで、セキュリティ境界の回避や、ユーザーのプライバシーに影響が生じ得ると示唆されています。ご利用のチームは、アップデートをお急ぎください。 #Chrome #CVE20261504 #Google #Vulnerability

    Post summary

    Google Chrome's critical vulnerability CVE-2026-1504, affecting the Background Fetch API, has been fixed by an urgent update; no exploit details or active exploitation were reported.

    02001280
    483 followersView on X
  • CSIRT TELCONET@CSIRT_Telconet
    Patch

    Chrome 144.0.7559.109/110 corrige la vulnerabilidad crítica CVE-2026-1504 en la Background Fetch API, que podía permitir la manipulación de descargas en segundo plano y afecta a Windows, macOS y Linux. Mas información: https://csirt.telconet.net/comunicacion/boletines-servicios/actualizacion-de-seguridad-en-chrome-corrige-vulnerabilidad-critica-en-background-fetch-api/ https://t.co/2awGZmwvsU

    Post summary

    Chrome releases version 144.0.7559.109/110 that fixes the critical CVE-2026-1504 affecting the Background Fetch API on Windows, macOS, and Linux.

    01011171
    804 followersView on X
  • Truc Doan | Trudy@Trudylangs
    Disclosure

    Lần thứ 2 trong tháng 1/2026, Google xác nhận trình duyệt Chrome tồn tại lỗ hổng bảo mật nghiêm trọng và đã phát hành bản vá khẩn cấp. Mọi người đang sử dụng Chrome nên cập nhật lên phiên bản mới nhất để đảm bảo an toàn. Lỗ hổng có mã CVE-2026-1504, được đánh giá ở mức độ cao, liên quan đến Background Fetch API (cho phép ứng dụng web thực hiện tác vụ nền ngay cả khi người dùng đã đóng tab) Lỗ hổng này có thể bị lợi dụng để thực hiện các cuộc tấn công từ xa hoặc tấn công ngầm, ngay cả khi người dùng chỉ lướt web bình thường. • Phạm vi ảnh hưởng: Khoảng 3 tỷ người dùng Chrome trên toàn cầu đều có nguy cơ bị ảnh hưởng. • Tính âm thầm: Do lỗ hổng nằm trong cơ chế hoạt động nền (background), người dùng có thể không nhận ra dấu hiệu bất thường khi bị tấn công. • Rủi ro: Dù chưa có ghi nhận khai thác trong thực tế, Google hiện vẫn giữ kín chi tiết kỹ thuật, cho thấy khả năng bị khai thác là đáng lưu ý nếu người dùng chậm cập nhật. HƯỚNG DẪN CẬP NHẬT: 1. Mở Chrome → Nhấn vào Menu 3 chấm (⋮) ở góc phải. 2. Chọn "Trợ giúp" (Help) → "Giới thiệu về Google Chrome" (About Google Chrome). 3. Chờ trình duyệt tự động cập nhật lên phiên bản 144.0.7559.110 và nhấn "Khởi động lại" (Relaunch) Theo Cyber Press

    Post summary

    Google announced the CVE‑2026‑1504 vulnerability in Chrome’s Background Fetch API and issued a patch, urging users to update to mitigate potential remote exploits.

    00020119
    2.0K followersView on X
  • VulDB 🛡@vuldb
    General

    There is a new vulnerability with elevated criticality in Google Chrome (CVE-2026-1504) https://vuldb.com/?id.343131

    Post summary

    The statement merely announces the presence of a high‑criticality vulnerability (CVE‑2026‑1504) in Google Chrome, without any technical, exploit, or patch information.

    00011120
    2.1K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Disclosure

    TRC analysis shows Google accidentally disclosed CVE-2026-1504, an unpatched Chromium flaw allowing JavaScript to persist via Service Workers even after browser closure. Attackers can establish persistent C2 channels and maintain device access. Runtime egress controls help contain such browser-based persistence mechanisms. #ZeroDay #CloudSecurity 🔗 Full breakdown: https://aviatrix.ai/threat-research-center/google-chromium-unfixed-javascript-flaw-2026

    Post summary

    The tweet announces Google’s accidental disclosure of CVE‑2026‑1504, an unpatched Chromium flaw that lets JavaScript persist via Service Workers, potentially enabling persistent C2 channels; no PoC, exploit, patch, or evidence of active exploitation is provided.

    0000050
    1.9K followersView on X
  • WindowsForum@windowsforum
    Patch

    🔥 Edge now adds cross-platform policy support in Edge for Business management - IT can finally enforce the same rules everywhere. #WindowsForum #Edge https://windowsforum.com/threads/edge-144-0-3719-104-patch-adds-cross-platform-policies-and-cve-2026-1504-fix.399559/?utm_source=rss&utm_medium=rss

    Post summary

    The post announces that the latest Microsoft Edge patch adds cross‑platform policy support and includes a fix for CVE‑2026‑1504, highlighting the availability of a vendor fix.

    0000041
    993 followersView on X
  • Aakash Rahsi@rahsi_aaka
    Disclosure

    CVE-2026-1504 | Chromium: CVE-2026-1504 Inappropriate implementation in Background Fetch API https://www.aakashrahsi.online/post/cve-2026-1504 https://t.co/Pvvuiibqf5

    Post summary

    The tweet announces Chromium’s CVE‑2026‑1504, describing an inappropriate implementation of the Background Fetch API and linking to a post for more details.

    0000037
    2 followersView on X
  • 【學】@manabu2111
    Patch

    「Microsoft Edge」にもセキュリティ更新、v144.0.3719.104が安定チャネルでリリース - 窓の杜 https://forest.watch.impress.co.jp/docs/news/2082307.html 、以下の脆弱性が修正されたセキュリティアップデート、 CVE-2026-1504、Inappropriate implementation in Background Fetch API(High)

    Post summary

    Microsoft Edge released a security update (v144.0.3719.104) that patches CVE‑2026‑1504, an improperly implemented Background Fetch API issue classified as High severity.

    0000065
    2.2K followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Chrome 144 Patch Fixes High-Severity Background Fetch API Flaw (CVE-2026-1504) Google shipped Chrome 144.0.7559.109/.110 to fix CVE-2026-1504, a high-severity “inappropriate implementation” bug in the Background Fetch API that could enable unauthorized data handling or security-boundary confusion during background transfers—update and restart Chrome to apply the fix. 🎯 Target: Global/Chrome Users #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cyberpress.org/chrome-security-update-background-fetch-api-vulnerability/

    Post summary

    Google released Chrome 144 to address the high‑severity CVE‑2026‑1504 background fetch API flaw, advising users to update to the patched version.

    0000055
    196 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Chrome patches high-severity Background Fetch flaw (CVE-2026-1504) that can leak cross-origin data Google shipped Chrome 144.0.7559.109/110 to fix CVE-2026-1504, an “inappropriate implementation” in the Background Fetch API that allows a crafted web page to leak cross-origin data; details are limited until most users update, so the priority is upgrading immediately on Windows/macOS/Linux. 🎯 Target: Global/Chrome Users #️⃣ Category: #Vulnerability #BlueTeam #CyberIntel 🔗 URL: https://cybersecuritynews.com/chrome-fetch-api-vulnerability/

    Post summary

    Google has released a patch to fix a high‑severity Background Fetch API flaw (CVE‑2026‑1504) that allows crafted web pages to leak cross‑origin data; users are advised to update immediately.

    0000065
    196 followersView on X
  • 【學】@manabu2111
    Patch

    「Google Chrome」のBackground Fetch APIに脆弱性、修正更新が展開中 - 窓の杜 https://forest.watch.impress.co.jp/docs/news/2081312.html 、以下の1件の脆弱性が修正、 CVE-2026-1504、Inappropriate implementation inBackground Fetch API(High) 、深刻度の評価は、4段階中上から2番目の「High」、今の所悪用の報告はないようだ

    Post summary

    Google Chrome’s Background Fetch API vulnerability CVE‑2026‑1504 has been patched, with no known exploitation reported.

    0000081
    2.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-1504 Cross-Origin Data Leak in Google Chrome Background Fetch API Befor... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1504 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The text announces CVE‑2026‑1504, noting a cross‑origin data leak in Chrome’s Background Fetch API, without providing PoC, exploit, or patch information.

    0000084
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1504 Inappropriate implementation in Background Fetch API in Google Chrome prior to 144.0.7559.110 allowed a remote attacker to leak cross-origin data via a crafted HTML pag… https://www.cve.org/CVERecord?id=CVE-2026-1504

    Post summary

    CVE-2026-1504 reports a flaw in Chrome’s Background Fetch API enabling cross‑origin data leakage; no PoC, exploit code, or patch is referenced.

    00000255
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgooglechrome---

Explore more