Executive brief
A security vulnerability in Google Chrome's extension system could allow a malicious extension to bypass 'site isolation,' a critical security feature that keeps data from different websites separate. If a user is tricked into installing a specially crafted extension, the attacker could potentially access information from other websites the user has open. This could lead to the exposure of sensitive personal data or login credentials across different web services.
Technical details
A vulnerability classified as insufficient policy enforcement exists within the Extensions component of Google Chrome. The flaw allows a crafted Chrome Extension to bypass the Site Isolation security boundary, which is designed to ensure that content from different sites is always rendered in different worker processes. To exploit this, an attacker must use social engineering to convince a user to install a malicious extension. Once installed, the extension can circumvent cross-site restrictions to access data from other origins. The issue is resolved in Google Chrome version 149.0.7827.53.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
- 2026-06-04: disclosed: NVD publication date