CVE List

CVE-2026-1504

Moderate 6.5

Inappropriate implementation in Background Fetch API in Google Chrome prior to 144.0.7559.110 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

Published January 27, 2026.

Affected software

Get alerts for Google Chrome

Reference links