Junglewise Threat Intelligence

CVE-2026-17779: Google Chrome Site Isolation bypass via crafted HTML page

CVE-2026-17779 · Severity: info · CVSS 4.3 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's Site Isolation feature could allow a malicious website to bypass security boundaries. Site Isolation is a critical security layer that keeps data from different websites separate to prevent one site from stealing information from another. If exploited, an attacker could potentially access data from other open tabs or websites through a specially crafted webpage.

Technical details

An inappropriate implementation in the Site Isolation component of Google Chrome allowed for a security bypass. By enticing a user to visit a specially crafted HTML page, a remote attacker could circumvent the process-based boundaries intended to keep web content separated. This could lead to the unauthorized access of data across different origins. The vulnerability is addressed in Chrome version 151.0.7922.72.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in Chrome Stable channel update 151.0.7922.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats