Executive brief
Google Chrome is a widely used web browser. A security vulnerability in its Site Isolation feature could allow a remote attacker who has already compromised a website's rendering process to escape the browser's security sandbox. This could potentially allow the attacker to interact with other parts of the system or access data they should not have permission to see.
Technical details
An improper input validation vulnerability (CWE-20) exists in the SiteIsolation component of Google Chrome for Windows. The flaw is triggered when the browser fails to sufficiently validate untrusted input, which can be exploited by a remote attacker who has already achieved code execution within a compromised renderer process. By utilizing a specially crafted HTML page, the attacker can potentially perform a sandbox escape. This vulnerability was addressed in version 149.0.7827.53. The Chromium project assigned this a 'Medium' severity rating.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
- 2026-06-04: disclosed: CVE published.