Executive brief
Google Chrome's SiteIsolation security feature contains an input validation flaw that allows an attacker who has already compromised the renderer process to escape the browser sandbox and execute arbitrary code. This could enable attackers to break out of the browser sandbox protection layer and gain broader system access when exploiting renderer process vulnerabilities.
Technical details
This vulnerability is an improper input validation flaw in Chrome's SiteIsolation feature, a security architecture designed to isolate web pages from each other and prevent cross-site attacks. An attacker who has compromised the renderer process can craft a malicious HTML page to bypass input validation checks and escape the sandbox environment, achieving arbitrary code execution outside the sandbox boundaries. The attack requires prior renderer process compromise and the victim to open a crafted HTML page. The vulnerability was patched in Chrome 153.0.8010.36. Given the Chromium security severity rating of Medium but the reported CVSS 8.3 (High) and reported severity (High), this represents a significant post-compromise escalation risk.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched: Chrome 153.0.8010.36 released