Junglewise Threat Intelligence

CVE-2026-78953: Google Chrome authorization bypass in SiteIsolation

CVE-2026-78953 · Severity: low · CVSS 3.1 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's SiteIsolation feature is a security boundary designed to prevent malicious websites from accessing data across different sites. This vulnerability allows an attacker who has already compromised Chrome's internal rendering process to bypass that protection using a specially crafted PDF file, potentially gaining access to sensitive user data from other sites that should be isolated from one another.

Technical details

This is an authorization bypass in Google Chrome's SiteIsolation mechanism, a core security feature that isolates web pages from different origins in separate processes. The vulnerability exists in versions prior to 152.0.7977.65 and requires an attacker to have already compromised the renderer process—a high barrier to entry that significantly limits practical exploitation. An attacker can exploit this by providing a crafted PDF file that, when processed by the compromised renderer, bypasses the site isolation boundary. The vulnerability was reported with a CVSS score of 3.1 and has not been observed in active exploitation. A patch is available in Chrome 152.0.7977.65 and later.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats