Executive brief
A vulnerability in Google Chrome's media handling on Windows could allow a malicious website to bypass security boundaries. Specifically, it weakens 'site isolation,' a feature designed to keep data from different websites separate. An attacker could exploit this by tricking a user into visiting a specially crafted webpage, potentially allowing the attacker to access information they should not be able to see.
Technical details
A vulnerability classified as insufficient policy enforcement exists in the Media component of Google Chrome for Windows. The flaw allows a remote attacker to bypass Site Isolation, a security boundary that ensures content from different sites is rendered in separate processes. By convincing a user to visit a maliciously crafted HTML page, the attacker can exploit this lack of enforcement to potentially access cross-site data. This issue is resolved in Chrome version 150.0.7871.47 and later.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched