Security Advisory Desk
unratedQCS priority 70/100Microsoft

CVE-2026-76019: Chromium CVE-2026-76019: Incorrect authorization in Workers

A security flaw was found and fixed in the Chromium open-source browser engine, which Microsoft Edge (Chromium-based) uses. This flaw involved incorrect permission checks in a feature that runs background scripts, called Workers. The latest version of Microsoft Edge includes the fix, so users should update to stay protected.

Published 8/9/2026, 7:00:00 amVerified 13/9/2026, 9:47:09 amRevision 1
Microsoft unrated network security advisory visual

In plain language

What this advisory means

A security flaw was found and fixed in the Chromium open-source browser engine, which Microsoft Edge (Chromium-based) uses. This flaw involved incorrect permission checks in a feature that runs background scripts, called Workers. The latest version of Microsoft Edge includes the fix, so users should update to stay protected.

Technical explanation

How the issue affects the environment

CVE-2026-76019 is an authorization vulnerability within Chromium's Workers subsystem. Workers execute scripts in the background to improve web performance. In this issue, the system failed to properly verify authorization, potentially allowing unauthorized actions by scripts running in a Worker context. Microsoft Edge (Chromium-based) incorporates Chromium and has updated to version 151.0.4129.107, which includes the upstream fix resolving this incorrect authorization flaw.

Operational impact

Why teams should care

If not addressed, this vulnerability could allow malicious web content to misuse Workers to perform unauthorized operations, potentially compromising user data and web session integrity. Updating Microsoft Edge mitigates this risk by ensuring the proper authorization checks are enforced.

Immediate action

Users and administrators should update Microsoft Edge (Chromium-based) to version 151.0.4129.107 or later to obtain the fix included from the Chromium project addressing this issue.

Affected and fixed releases

Affected versionsConfirm in the official vendor advisory
Fixed versions151.0.4129.107

Temporary risk reduction

No separate workaround was supplied in the source feed. Use the official vendor advisory before changing production controls.

Evidence and validation checklist

  • Microsoft Advisory states that the issue is in Chromium and fixed in Microsoft Edge version 151.0.4129.107.
  • Microsoft notes that Chromium's fix is ingested into Microsoft Edge (Chromium-based).
  • Official source provides update link and confirms version information for remediation.
  • No separate detailed technical description or exploitation status is provided by Microsoft.

Authoritative reference

Microsoft Security Response Center

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source