Executive brief
Google Chrome is a widely used web browser. A security flaw in its compositing component could allow a malicious website to bypass 'site isolation,' a critical security feature that keeps data from different websites separate. If exploited, an attacker who has already partially compromised the browser could potentially access information from other open websites or tabs.
Technical details
An improper input validation vulnerability (CWE-20) exists in the Compositing component of Google Chrome. The flaw allows a remote attacker who has already compromised the renderer process to bypass site isolation protections. By convincing a user to visit a specially crafted HTML page, the attacker can leverage this insufficient validation to access data across site boundaries. This issue was resolved in Chrome version 147.0.7727.138.
Affected products
- Google Chrome prior to 147.0.7727.138
Timeline
- 2026-03-24: other: Reported by Google internal researchers
- 2026-04-28: disclosed
- 2026-04-28: patched: Fixed in version 147.0.7727.138