Junglewise Threat Intelligence

CVE-2026-15131: Google Chrome site isolation bypass in Navigation

CVE-2026-15131 · Severity: info · Published 2026-07-08

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its navigation component could allow a malicious website to bypass 'site isolation,' a security feature that keeps data from different websites separate. If exploited, this could allow an attacker to access information from other open tabs or websites that should remain protected.

Technical details

An inappropriate implementation and insufficient data validation in the Navigation component of Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypass site isolation. By convincing a user to visit a specially crafted HTML page, an attacker could potentially access data across security boundaries that are normally enforced by the browser's process-per-site model. This issue is categorized by Chromium as Medium severity. Users are advised to update to version 150.0.7871.115 or later.

Affected products

  • Google Chrome prior to 150.0.7871.115

Timeline

  • 2026-06-22: disclosed: Reported to Google
  • 2026-07-08: patched: Fixed in Stable Channel Update 150.0.7871.115
  • 2026-07-08: advisory

References

Related threats