Google released Chrome 144.0.7559.109/.110 to the Stable channel for Windows, macOS, and Linux to remediate a high-severity vulnerability in the Background Fetch API, tracked as CVE-2026-1504 (CVSS 7.5) and described as an “inappropriate implementation.” The Background Fetch API enables websites to continue large downloads in the background even after a user closes a tab or navigates away, and the flaw could allow malicious sites to manipulate background fetch operations; detailed exploitation information is being withheld until most users have applied the update.
The issue was reported on January 9, 2026 by security researcher Luan Herrera (@lbherrera_) and earned a $3,000 reward via Google’s Vulnerability Reward Program. Google stated the fix is included in the Stable builds and is rolling out gradually over days to weeks, with guidance for users to manually update via Help → About Google Chrome to ensure the patched version is installed.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Google released Chrome Stable updates 144.0.7559.109/110 for Windows and macOS and 144.0.7559.109 for Linux to fix CVE-2026-1504, an inappropriate implementation in the Background Fetch API. The rollout began on January 28, 2026, with technical details withheld until most users update.
External researcher Luan Herrera reported a high-severity Chrome vulnerability in the Background Fetch API, later assigned CVE-2026-1504. Google awarded a $3,000 bounty through its Vulnerability Reward Program.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.