Executive brief
Google Chrome is a widely used web browser. A vulnerability in its navigation component could allow a malicious website to bypass 'site isolation,' a security feature that keeps data from different websites separate. If exploited, this could allow an attacker to access information from other open tabs or websites that should remain protected.
Technical details
An inappropriate implementation and insufficient data validation in the Navigation component of Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypass site isolation. By convincing a user to visit a specially crafted HTML page, an attacker could potentially access data across security boundaries that are normally enforced by the browser's process-per-site model. This issue is categorized by Chromium as Medium severity. Users are advised to update to version 150.0.7871.115 or later.
Affected products
- Google Chrome prior to 150.0.7871.115
Timeline
- 2026-06-22: disclosed: Reported to Google
- 2026-07-08: patched: Fixed in Stable Channel Update 150.0.7871.115
- 2026-07-08: advisory