Executive brief
A vulnerability in Google Chrome's Reading Mode on macOS could allow a remote attacker to bypass security boundaries. If an attacker has already compromised a user's browser rendering process, they could use a specially crafted webpage to access data from other websites that should normally be isolated. This could lead to the unauthorized exposure of sensitive user information across different web sessions.
Technical details
An improper input validation vulnerability exists in the ReadingMode component of Google Chrome on macOS. The flaw allows a remote attacker who has already achieved code execution within a compromised renderer process to bypass Site Isolation protections via a crafted HTML page. Site Isolation is a critical security boundary in Chromium designed to ensure that pages from different websites are run in separate processes. By bypassing this, an attacker could potentially access sensitive data belonging to other origins. The issue is addressed in version 148.0.7778.168 for Mac.
Affected products
- Google Chrome Prior to 148.0.7778.168
Timeline
- 2026-03-24: disclosed: Reported to Chromium project by Google internal researchers
- 2026-05-12: patched: Fixed in Chrome Stable channel update 148.0.7778.168
- 2026-05-14: advisory: NVD publication date