Executive brief
Google Chrome for Android is a mobile web browser used to access the internet. A security flaw in the way the browser handles user input could allow a malicious website to bypass 'site isolation,' a critical security feature that keeps data from different websites separate. If exploited, an attacker who has already gained partial control of the browser could access sensitive information from other open websites or accounts.
Technical details
A vulnerability exists in the Input component of Google Chrome for Android due to an inappropriate implementation. An attacker who has already compromised the renderer process can exploit this flaw by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to bypass site isolation protections, which are designed to ensure that pages from different sites run in separate processes and cannot access each other's data. This could lead to cross-site data leakage or further compromise of the user's browsing session. The issue is resolved in version 148.0.7778.216.
Affected products
- Google Chrome prior to 148.0.7778.216
Timeline
- 2026-05-27: patched: Stable channel update released for desktop and Android.
- 2026-05-28: disclosed: CVE published to the NVD.