Executive brief
Google Chrome is a widely used web browser. A security flaw in how the browser handles plugins could allow a malicious website to bypass 'site isolation,' a critical security feature that keeps data from different websites separate. If an attacker has already partially compromised the browser's rendering process, they could use this vulnerability to access sensitive information from other open websites or tabs.
Technical details
This vulnerability is classified as an inappropriate implementation within the Plugins component of Google Chrome. The flaw allows a remote attacker to bypass Site Isolation, a security boundary designed to ensure that pages from different websites run in separate processes. To exploit this, an attacker must first achieve a compromise of the renderer process (e.g., via a separate memory corruption bug). Once the renderer is compromised, the attacker can use a specially crafted HTML page to break out of the isolation sandbox and access data from other origins. This issue was fixed in Google Chrome version 149.0.7827.103.
Affected products
- Google Chrome prior to 149.0.7827.103
Timeline
- 2026-05-28: other: Reported by Google researchers
- 2026-06-08: patched: Fixed in stable channel update 149.0.7827.103
- 2026-06-09: disclosed: NVD publication date