Junglewise Threat Intelligence

CVE-2026-12457: Google Chrome site isolation bypass in Extensions

CVE-2026-12457 · Severity: medium · CVSS 4.2 · Published 2026-06-17

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security flaw in Google Chrome's extension system could allow a malicious website to bypass the browser's built-in security boundaries. If an attacker has already partially compromised the browser's rendering process, they could use this vulnerability to access data from other websites that should normally be isolated. This could lead to the unauthorized viewing or modification of sensitive user information across different web sessions.

Technical details

This vulnerability is classified as a protection mechanism failure (CWE-693) within the Extensions component of Google Chrome. The root cause is an inappropriate implementation/insufficient data validation that fails to strictly enforce site isolation boundaries. An attacker who has already achieved code execution within a compromised renderer process can exploit this flaw by using a specially crafted HTML page to bypass Site Isolation. This allows the attacker to access or interfere with data belonging to other origins, which is a violation of the browser's security model. The issue was addressed in Chrome version 149.0.7827.155.

Affected products

  • Google Chrome prior to 149.0.7827.155

Timeline

  • 2026-05-27: disclosed: Reported to Google by internal/external researchers.
  • 2026-06-16: patched: Fixed in stable channel update 149.0.7827.155.
  • 2026-06-17: advisory: NVD publication date.

References

Related threats