Executive brief
Chrome is a web browser used by billions of users to access websites and web applications. This vulnerability allows an attacker who has already compromised Chrome's rendering process to bypass site isolation—a critical security feature that prevents malicious websites from accessing data from other websites. This could lead to unauthorized cross-site data theft.
Technical details
The vulnerability is an improper control of a resource through its lifetime in Chrome's Workers component. The flaw exists in Google Chrome versions prior to 152.0.7977.65. It requires an attacker to have already compromised the renderer process, and then craft a malicious HTML page to trigger the vulnerability. A successful exploit allows an attacker to bypass site isolation, potentially accessing sensitive data from other websites. The vulnerability is patched in Chrome 152.0.7977.65 and later versions.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Chrome 152.0.7977.65