Junglewise Threat Intelligence

CVE-2026-17659: Google Chrome site isolation bypass in SiteIsolation

CVE-2026-17659 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A security vulnerability was identified in its Site Isolation feature, which is designed to keep data from different websites separate. If an attacker first compromises the browser's rendering process, they could use this flaw to bypass these security boundaries, potentially accessing sensitive information from other open websites or user sessions.

Technical details

A vulnerability classified as an inappropriate implementation in the SiteIsolation component of Google Chrome exists in versions prior to 151.0.7922.72. The flaw allows a remote attacker to bypass site isolation boundaries. A precondition for this exploit is that the attacker must have already achieved code execution within a compromised renderer process. By utilizing a specially crafted HTML page, the attacker can then break out of the process sandbox or access data across origins that Site Isolation is intended to protect. Google has addressed this issue in the stable channel update 151.0.7922.72.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-03-23: disclosed: Reported to Chromium by Google researchers
  • 2026-07-29: patched: Fixed in Chrome Stable channel update 151.0.7922.72
  • 2026-07-30: advisory: NVD publication date

References

Related threats