Junglewise Threat Intelligence

CVE-2026-7360: Google Chrome site isolation bypass in Compositing

CVE-2026-7360 · Severity: low · CVSS 3.1 · Published 2026-04-28

Technologies: Apple macOS, Microsoft Windows, Google Chrome, Linux Kernel. Vendors: Apple, Microsoft, Google, Linux.

Executive brief

Google Chrome is a widely used web browser. A security flaw in its compositing component could allow a malicious website to bypass 'site isolation,' a critical security feature that keeps data from different websites separate. If exploited, an attacker who has already partially compromised the browser could potentially access information from other open websites or tabs.

Technical details

An improper input validation vulnerability (CWE-20) exists in the Compositing component of Google Chrome. The flaw allows a remote attacker who has already compromised the renderer process to bypass site isolation protections. By convincing a user to visit a specially crafted HTML page, the attacker can leverage this insufficient validation to access data across site boundaries. This issue was resolved in Chrome version 147.0.7727.138.

Affected products

  • Google Chrome prior to 147.0.7727.138

Timeline

  • 2026-03-24: other: Reported by Google internal researchers
  • 2026-04-28: disclosed
  • 2026-04-28: patched: Fixed in version 147.0.7727.138

References

Related threats