Executive brief
A security vulnerability in Google Chrome's navigation component could allow a remote attacker to bypass site isolation protections. Site isolation is a critical security feature that ensures websites cannot access data from other websites. If exploited, an attacker who has already partially compromised the browser's rendering process could use a specially crafted webpage to access sensitive information from other open tabs or sites.
Technical details
An improper input validation vulnerability (CWE-20) exists in the Navigation component of Google Chrome. The flaw allows a remote attacker who has already compromised the renderer process to bypass Site Isolation boundaries. By convincing a user to visit a specially crafted HTML page, the attacker can leverage insufficient validation of untrusted input to escape the restricted environment of a single site. This vulnerability was addressed in Chrome version 149.0.7827.53.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
- 2026-06-04: disclosed: CVE published.