Executive brief
Google Chrome contains a security vulnerability in its extension system that could allow a malicious extension to bypass site isolation protections. Site isolation is a critical security feature that keeps data from different websites separate to prevent one site from stealing information from another. If a user is tricked into installing a specially crafted malicious extension, the attacker could potentially access data from other websites the user has open, compromising sensitive personal or corporate information.
Technical details
A policy bypass vulnerability exists in the Extensions component of Google Chrome prior to version 151.0.7922.72. The flaw allows a crafted Chrome Extension to bypass site isolation, a security boundary designed to ensure that content from different sites is always rendered in different processes. To exploit this, an attacker must convince a user to install a malicious extension. Once installed, the extension can leverage this bypass to access data across origin boundaries that should be protected by the browser's process-level isolation. The issue is addressed in Chrome version 151.0.7922.72.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched
- 2026-07-30: disclosed