Executive brief
A vulnerability in Google Chrome's Site Isolation feature could allow an attacker to bypass security boundaries between different websites. Site Isolation is a critical security layer that ensures pages from different sites run in separate processes to prevent them from stealing each other's data. If an attacker has already compromised a browser's rendering process, they could use this flaw to access information from other open tabs or websites, potentially leading to the theft of sensitive user data or session information.
Technical details
A vulnerability exists in Google Chrome's SiteIsolation component due to insufficient validation of untrusted input. An attacker who has already achieved code execution within a compromised renderer process can exploit this flaw via a specially crafted HTML page to bypass Site Isolation boundaries. This bypass allows the compromised process to potentially access or interact with data from other origins that should be isolated. The issue is addressed in Chrome version 148.0.7778.168. While the reported CVSS is 4.3, Chromium classifies the internal severity as High.
Affected products
- Google Chrome prior to 148.0.7778.168
Timeline
- 2026-02-26: disclosed: Reported by Google internal researchers
- 2026-05-12: patched: Fixed in Stable Channel Update 148.0.7778.168
- 2026-05-14: advisory: NVD publication date