Junglewise Threat Intelligence

CVE-2026-78903: Google Chrome SiteIsolation bypass in incomplete cleanup

CVE-2026-78903 · Severity: low · CVSS 3.1 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's SiteIsolation feature provides security isolation between websites to prevent malicious sites from accessing data from other sites. A flaw in cleanup logic allowed an attacker with control over the browser's rendering process to bypass this isolation through a crafted webpage, potentially exposing user data across site boundaries. This is a lower-risk vulnerability as it requires the attacker to first compromise Chrome's internal renderer process.

Technical details

The vulnerability exists in Google Chrome's SiteIsolation mechanism, which is responsible for isolating renderer processes between different websites. Incomplete cleanup logic fails to properly reset state when transitioning between sites, allowing an attacker who has already compromised a renderer process to craft an HTML page that exploits this cleanup gap to bypass site isolation boundaries. The attack requires prior compromise of the renderer process itself, making it a post-compromise attack rather than a primary entry vector. Google patched this issue in Chrome version 152.0.7977.65 or later. The Chromium security team classified this as Medium severity internally, though the official CVSS rating is 3.1 (Low).

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Chrome 152.0.7977.65

References

Related threats