Executive brief
A security vulnerability in Google Chrome allowed attackers to bypass critical security boundaries that keep different websites isolated from one another. If an attacker first compromises the browser's rendering process, they could use this flaw to access data from other open websites or tabs. This could lead to the exposure of sensitive user information or session data across different web domains.
Technical details
An improper input validation vulnerability (CWE-20) exists in the Input component of Google Chrome. A remote attacker who has already achieved code execution within a compromised renderer process could exploit this flaw via a specially crafted HTML page. Successful exploitation allows the attacker to bypass Site Isolation, a security feature designed to ensure that pages from different websites run in separate processes. This bypass could enable the attacker to access sensitive data or perform actions across origin boundaries. The issue is resolved in Chrome version 148.0.7778.216 and later.
Affected products
- Google Chrome Prior to 148.0.7778.216
Timeline
- 2026-05-27: patched: Stable channel update released for Desktop
- 2026-05-28: disclosed: NVD publication date