securityonline.info 1/28/2026, 4:15:29 AM · via preferred

Chrome Patches High-Severity Background Fetch Flaw (CVE-2026-1504)

Chrome Patches High-Severity Background Fetch Flaw (CVE-2026-1504)
CyberSIXT Evidence Panel
CVE Intel
CISA KEV Not in KEV
Patch Patch Available

GOOGLE has rolled out an update for the Chrome Stable channel to address CVE-2026-1504, described as an “Inappropriate implementation in Background Fetch API.” The patch pushes version 144.0.7559.109/110 to Windows and Mac users, with Linux receiving 144.0.7559.109, and the update is rolling out in the coming days and weeks. The Background Fetch API enables websites to manage downloads of large files even if the user closes the tab, but flaws in such mechanisms can be exploited to misbehave or compromise data.

The flaw was reported on 9 January 2026 by external security researcher Luan Herrera, and the fix arrived swiftly in the stable channel; the updated builds are intended to close the potential attack vector. Users are urged to force the update to ensure protection, following steps to open Chrome, access Help > About Google Chrome, and install version 144.0.7559.109 (or .110).

View full article

Article by CyberSIXT