Executive brief
Google Chrome's Site Isolation security feature, which separates websites into independent processes to prevent data theft, contains an authorization flaw in Chrome versions prior to 153.0.8010.36. An attacker who has already compromised the renderer process can exploit this to bypass system access restrictions, potentially accessing data that should be protected. This affects Windows, Mac, and Linux users until they update to the patched version.
Technical details
The vulnerability is an incorrect authorization issue in Chrome's SiteIsolation mechanism, which normally enforces process isolation between websites. The flaw allows a remote attacker who has already compromised the renderer process to bypass system access restrictions via a specially crafted HTML page. While the attack requires a renderer process compromise as a precondition, the vulnerability enables privilege escalation within the browser's multi-process architecture. The fix is available in Chrome 153.0.8010.36 and later for Windows, Mac, and Linux.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched: Chrome 153.0.8010.36 released