Junglewise Threat Intelligence

CVE-2026-13868: Google Chrome site isolation bypass in Network component

CVE-2026-13868 · Severity: info · CVSS 4.3 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability in Google Chrome for Android could allow a malicious website to bypass 'site isolation,' a core security feature that keeps data from different websites separate. If an attacker has already compromised a part of the browser's rendering engine, they could use a specially crafted webpage to access information from other open sites. This could lead to the unauthorized viewing of sensitive user data or session information from other web services.

Technical details

An inappropriate implementation in the Network component of Google Chrome on Android allowed for a site isolation bypass. The vulnerability requires a multi-stage attack: first, the attacker must compromise the renderer process (typically via a separate exploit), and then use a crafted HTML page to trigger the flaw. This bypass allows the compromised renderer to break out of its security sandbox and access data from other origins, violating the Same-Origin Policy. The issue is fixed in version 150.0.7871.47 and later.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats