Junglewise Threat Intelligence

CVE-2026-13866: Google Chrome site isolation bypass in Input

CVE-2026-13866 · Severity: info · CVSS 0 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome for Android is a mobile web browser used to access the internet. A security flaw in how the browser handles user input could allow a malicious website to bypass 'site isolation,' a critical security feature that keeps data from different websites separate. If exploited, an attacker who has already gained a foothold in the browser's processing engine could potentially access information from other open websites or tabs.

Technical details

An inappropriate implementation vulnerability exists in the Input component of Google Chrome for Android prior to version 150.0.7871.47. The flaw allows a remote attacker who has already compromised the renderer process to bypass site isolation protections using a specially crafted HTML page. This is classified as improper input validation (CWE-20). By bypassing site isolation, the attacker can potentially access data across different security domains that should be isolated. The issue is addressed in version 150.0.7871.47 and later.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: advisory: NVD and Chrome Release blog published advisory
  • 2026-06-30: patched: Fixed in version 150.0.7871.47

References

Related threats