Junglewise Threat Intelligence

CVE-2026-12017: Google Chrome site isolation bypass in Extensions

CVE-2026-12017 · Severity: info · CVSS 8.8 · Published 2026-06-11

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability in Google Chrome's extension system could allow a malicious website to bypass critical security boundaries. If an attacker has already partially compromised the browser's rendering process, they could use this flaw to access data from other websites or the user's local system. This bypasses 'Site Isolation,' a primary defense mechanism designed to keep data from different websites separate and secure.

Technical details

This vulnerability is classified as an inappropriate implementation/insufficient validation of untrusted input within the Extensions component of Google Chrome. The flaw allows a remote attacker who has already achieved code execution within a compromised renderer process to bypass Site Isolation protections. By utilizing a specially crafted HTML page, the attacker can break out of the sandboxed renderer process to access data across different origins. This issue was addressed in Chrome version 149.0.7827.115. While the NVD entry lists the severity as 'High' per Chromium's internal assessment, a formal CVSS score is not yet provided; however, similar site isolation bypasses typically reach High severity due to the impact on confidentiality and integrity.

Affected products

  • Google Chrome prior to 149.0.7827.115

Timeline

  • 2026-05-26: disclosed: Reported to Google by internal researchers.
  • 2026-06-11: patched: Fixed in Stable Channel Update 149.0.7827.114/.115.
  • 2026-06-11: advisory: NVD and Chrome Release blog published.

References

Related threats