Executive brief
A security vulnerability in Google Chrome's GuestView component could allow a remote attacker to bypass site isolation protections. This component is responsible for displaying web content from different sources within a single page or extension. If exploited, an attacker who has already partially compromised the browser could access data from other websites, potentially leading to the theft of sensitive user information or session credentials.
Technical details
This vulnerability is classified as insufficient policy enforcement within the GuestView component of Google Chrome. The flaw allows a remote attacker who has already achieved code execution within a compromised renderer process to bypass Site Isolation, a critical security boundary that ensures content from different websites is kept in separate processes. By utilizing a specially crafted HTML page, the attacker can break these process boundaries to access data across different origins. The issue is addressed in Google Chrome version 150.0.7871.47 and later.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: advisory
- 2026-06-30: patched