Executive brief
Google Chrome's site isolation feature, a security mechanism designed to prevent one website from accessing data belonging to another, contains an authorization flaw. An attacker can craft a malicious HTML page to bypass this protection, potentially allowing unauthorized access to sensitive data from other websites that a user visits.
Technical details
CVE-2026-87468 is an incorrect authorization vulnerability in Chrome's Isolated component that fails to properly enforce site isolation boundaries. The flaw allows a remote attacker to craft a malicious HTML page that, when visited by a user, can bypass site isolation protections. No authentication or special user interaction beyond viewing the crafted page is required. An attacker can exploit this to access cross-origin data that should be protected by site isolation. The vulnerability was patched in Chrome 153.0.8010.36 and later versions.
Affected products
- Google Chrome before 153.0.8010.36
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched