Junglewise Threat Intelligence

CVE-2026-11220: Google Chrome site isolation bypass in Navigation

CVE-2026-11220 · Severity: info · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability in Google Chrome's navigation component could allow a remote attacker to bypass site isolation protections. Site isolation is a critical security feature that ensures websites cannot access data from other websites. If exploited, an attacker who has already partially compromised the browser's rendering process could use a specially crafted webpage to access sensitive information from other open tabs or sites.

Technical details

An improper input validation vulnerability (CWE-20) exists in the Navigation component of Google Chrome. The flaw allows a remote attacker who has already compromised the renderer process to bypass Site Isolation boundaries. By convincing a user to visit a specially crafted HTML page, the attacker can leverage insufficient validation of untrusted input to escape the restricted environment of a single site. This vulnerability was addressed in Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
  • 2026-06-04: disclosed: CVE published.

References

Related threats