- Joined
- Jan 22, 2026
- Messages
- 101
- Reaction score
- 921
An error has been found in the browser that allows sites to bypass security restrictions.

Google has urgently closed a vulnerability in the Chrome browser that could imperceptibly pose security and privacy threats to the user. This is a problem with the background data download mechanism, which could theoretically allow attackers to access browser functions beyond acceptable limits. Users are encouraged to install the update as soon as possible.
The Chrome Stable Channel update updates the browser to versions 144.0.7559.109 and .110 for Windows and macOS, as well as 144.0.7559.109 for Linux. The fixed vulnerability was registered under the number CVE-2026-1504 and was rated CVSS: 6.5. Google reported that the problem is related to the incorrect implementation of the background data loading interface, which allows sites to download large files even when the tab is closed or the browser window is minimized.
The feature was created for user convenience, for example, to download videos, programs, or large documents without having to keep the page open. But it is the work in the background that makes such mechanisms particularly sensitive from a security point of view. According to Google, an error in the implementation could lead to circumvention of security restrictions, incorrect permission processing, and unsafe processing of background requests.
The company did not disclose the full technical details of the vulnerability. Google explained that access to the report is temporarily restricted so that attackers cannot analyze the fix and launch attacks on browsers that have not yet been updated. This approach is also used in cases where the vulnerability affects third-party libraries used in other projects.
The problem was reported on January 9, 2026, by information security researcher Luan Herrera. For discovering the vulnerability, he received a reward of $3,000 as part of the bug bounty program.
According to experts, the successful exploitation of the vulnerability could affect the security and privacy of users even without installing malware. In a corporate environment, this would create additional risks of data leaks and abuse of access rights on work devices.
Google strongly recommends updating Chrome via the browser's built-in update mechanism as soon as possible. Organizations are advised to force the latest version to be installed on employees' managed devices in order to reduce possible risks.

Google has urgently closed a vulnerability in the Chrome browser that could imperceptibly pose security and privacy threats to the user. This is a problem with the background data download mechanism, which could theoretically allow attackers to access browser functions beyond acceptable limits. Users are encouraged to install the update as soon as possible.
The Chrome Stable Channel update updates the browser to versions 144.0.7559.109 and .110 for Windows and macOS, as well as 144.0.7559.109 for Linux. The fixed vulnerability was registered under the number CVE-2026-1504 and was rated CVSS: 6.5. Google reported that the problem is related to the incorrect implementation of the background data loading interface, which allows sites to download large files even when the tab is closed or the browser window is minimized.
The feature was created for user convenience, for example, to download videos, programs, or large documents without having to keep the page open. But it is the work in the background that makes such mechanisms particularly sensitive from a security point of view. According to Google, an error in the implementation could lead to circumvention of security restrictions, incorrect permission processing, and unsafe processing of background requests.
The company did not disclose the full technical details of the vulnerability. Google explained that access to the report is temporarily restricted so that attackers cannot analyze the fix and launch attacks on browsers that have not yet been updated. This approach is also used in cases where the vulnerability affects third-party libraries used in other projects.
The problem was reported on January 9, 2026, by information security researcher Luan Herrera. For discovering the vulnerability, he received a reward of $3,000 as part of the bug bounty program.
According to experts, the successful exploitation of the vulnerability could affect the security and privacy of users even without installing malware. In a corporate environment, this would create additional risks of data leaks and abuse of access rights on work devices.
Google strongly recommends updating Chrome via the browser's built-in update mechanism as soon as possible. Organizations are advised to force the latest version to be installed on employees' managed devices in order to reduce possible risks.