Junglewise Threat Intelligence

CVE-2026-87541: Google Chrome information leak in site isolation

CVE-2026-87541 · Severity: medium · CVSS 6.5 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's site isolation feature—which prevents websites from accessing data from other sites—contains an information leak vulnerability. An attacker who compromises Chrome's renderer process can exploit this flaw through a malicious HTML page to bypass site isolation protections, potentially allowing unauthorized access to sensitive data from other domains. This affects Chrome versions before 153.0.8010.36.

Technical details

This vulnerability is an information leak in Chrome's Navigation component that undermines site isolation, a key security boundary designed to isolate web pages from different sites in separate renderer processes. The attack requires the attacker to have already compromised the renderer process, and then deliver a specially crafted HTML page to trigger the leak. Once triggered, the flaw allows the attacker to bypass site isolation protections and access cross-site data. The vulnerability is fixed in Chrome 153.0.8010.36 and later releases.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Chrome 153.0.8010.36 released

References

Related threats