Executive brief
Google Chrome is a widely used web browser. A security flaw in the browser's extension system could allow a malicious website to bypass 'site isolation,' a security feature that keeps data from different websites separate. If an attacker has already partially compromised the browser's rendering process, they could use this vulnerability to access information from other open websites or tabs.
Technical details
A policy enforcement vulnerability exists within the Extensions component of Google Chrome. The flaw allows a remote attacker who has already achieved code execution within a compromised renderer process to bypass Site Isolation protections. By utilizing a specially crafted HTML page, the attacker can break the process boundaries intended to separate web content. This could lead to unauthorized access to data across different origins. The issue is resolved in Google Chrome version 150.0.7871.47 and later.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched