Junglewise Threat Intelligence

CVE-2026-8528: Google Chrome Site Isolation bypass in SiteIsolation

CVE-2026-8528 · Severity: medium · CVSS 4.3 · Published 2026-05-14

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's Site Isolation feature could allow an attacker to bypass security boundaries between different websites. Site Isolation is a critical security layer that ensures pages from different sites run in separate processes to prevent them from stealing each other's data. If an attacker has already compromised a browser's rendering process, they could use this flaw to access information from other open tabs or websites, potentially leading to the theft of sensitive user data or session information.

Technical details

A vulnerability exists in Google Chrome's SiteIsolation component due to insufficient validation of untrusted input. An attacker who has already achieved code execution within a compromised renderer process can exploit this flaw via a specially crafted HTML page to bypass Site Isolation boundaries. This bypass allows the compromised process to potentially access or interact with data from other origins that should be isolated. The issue is addressed in Chrome version 148.0.7778.168. While the reported CVSS is 4.3, Chromium classifies the internal severity as High.

Affected products

  • Google Chrome prior to 148.0.7778.168

Timeline

  • 2026-02-26: disclosed: Reported by Google internal researchers
  • 2026-05-12: patched: Fixed in Stable Channel Update 148.0.7778.168
  • 2026-05-14: advisory: NVD publication date

References

Related threats