Junglewise Threat Intelligence

CVE-2026-11234: Google Chrome site isolation bypass in FoldableAPIs

CVE-2026-11234 · Severity: info · CVSS 0 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability in Google Chrome's FoldableAPIs could allow a malicious website to bypass security boundaries. If an attacker has already partially compromised the browser's rendering process, they could use this flaw to access data from other websites, undermining the 'site isolation' feature that keeps user data separate. This could lead to the unauthorized access of sensitive information across different open tabs or web sessions.

Technical details

A vulnerability exists in the FoldableAPIs component of Google Chrome due to an inappropriate implementation. An attacker who has already achieved remote code execution within a compromised renderer process can exploit this flaw using a specially crafted HTML page to bypass Site Isolation. Site Isolation is a critical security boundary in Chromium designed to ensure that pages from different sites are run in different low-privileged processes. By bypassing this, an attacker could potentially access sensitive data (such as cookies or stored credentials) from other origins. This issue is resolved in Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
  • 2026-06-04: disclosed: CVE published in NVD.

References

Related threats