Executive brief
A vulnerability in Google Chrome's navigation component could allow a malicious website to bypass security boundaries designed to keep different websites isolated from one another. In practice, this could allow an attacker to potentially access sensitive data from other open tabs or websites. Users are protected by updating to the latest version of the Chrome browser.
Technical details
A vulnerability classified as insufficient policy enforcement exists in the Navigation component of Google Chrome. The flaw allows a remote attacker to bypass Site Isolation, a security feature that ensures pages from different websites are run in separate processes. By tricking a user into visiting a specially crafted HTML page, an attacker could potentially access data across site boundaries. The issue is fixed in Chrome version 150.0.7871.115 for Windows and Mac, and 150.0.7871.114 for Linux.
Affected products
- Google Chrome prior to 150.0.7871.115
Timeline
- 2026-06-22: disclosed: Reported to Google
- 2026-07-08: patched: Stable channel update released
- 2026-07-08: advisory: NVD publication date