Executive brief
Google Chrome, a widely used web browser, contained a security vulnerability in its password management component. An attacker who had already partially compromised the browser's rendering process could use a specially crafted web page to bypass 'site isolation,' a critical security feature that keeps data from different websites separate. This could potentially allow an attacker to access sensitive information from other websites that should have been protected.
Technical details
An improper input validation vulnerability (CWE-20) existed in the Passwords component of Google Chrome prior to version 151.0.7922.72. The flaw allowed a remote attacker who had already achieved code execution within a compromised renderer process to bypass Site Isolation protections. By utilizing a specially crafted HTML page, the attacker could escape the sandbox constraints intended to isolate web origins. This vulnerability is rated as High severity by Chromium. Users are advised to update to version 151.0.7922.72 or later.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-05-27: disclosed: Reported to Chromium by Google researchers
- 2026-07-29: patched: Fixed in Stable Channel Update 151.0.7922.72
- 2026-07-30: advisory: NVD publication date