Executive brief
A vulnerability in Google Chrome's extension system could allow a remote attacker to bypass security boundaries that normally keep different websites isolated from one another. For this to occur, the attacker must first compromise the browser's rendering process, typically by tricking a user into visiting a malicious website. If successful, the attacker could potentially access data from other open websites or tabs, undermining the privacy and security protections of the browser.
Technical details
An inappropriate implementation vulnerability exists in the Extensions component of Google Chrome. The flaw allows a remote attacker who has already achieved code execution within a compromised renderer process to bypass Site Isolation protections. By utilizing a specially crafted HTML page, the attacker can break out of the sandboxed renderer process to access data across different origins. This issue is addressed in Google Chrome version 151.0.7922.72.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in Chrome Stable channel update 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date