Executive brief
Google Chrome is a widely used web browser. A security flaw in its 'Fenced Frames' feature—a mechanism designed to isolate embedded content—could allow a malicious website to bypass security boundaries. If an attacker has already partially compromised the browser's processing engine, they could use this vulnerability to access data from other websites that should remain isolated.
Technical details
This vulnerability is classified as an inappropriate implementation within the Fenced Frames component of Google Chrome. Fenced Frames are a privacy-focused feature designed to prevent communication between the frame and the embedding page. The flaw allows a remote attacker who has already achieved code execution within a compromised renderer process to bypass Site Isolation protections. By utilizing a specially crafted HTML page, the attacker can break the security boundary intended to keep different web origins separate. This issue was addressed in Chrome version 149.0.7827.53.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
- 2026-06-04: disclosed: CVE published in NVD.