Executive brief
A security issue in Google Chrome's Site Isolation feature could allow an attacker to bypass security boundaries between different websites. If an attacker has already compromised a browser's rendering process, they could use a specially crafted webpage to access data from other open sites. This could lead to the unauthorized viewing of sensitive information from different web services used by the victim.
Technical details
A vulnerability exists in the Site Isolation implementation of Google Chrome due to an inappropriate implementation. An attacker who has already achieved code execution within a compromised renderer process can exploit this flaw using a crafted HTML page to bypass the security boundaries that separate different web origins. This bypass allows the attacker to access data or interact with sites they should not have access to. The vulnerability is mitigated by the requirement of a pre-existing renderer compromise. Google has addressed this issue in Chrome version 149.0.7827.53.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Fixed in Chrome 149.0.7827.53 stable channel update.
- 2026-06-04: disclosed: CVE published to NVD.