Description
Insufficient policy enforcement in Media in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-06-30
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An insufficient policy enforcement flaw in the Media component of Google Chrome on Windows allows a remote attacker to bypass the browser’s site isolation boundary by serving a specially crafted HTML page. This improper access control issue (CWE‑602) lets the attacker read or modify data that is normally confined to a separate process, undermining cross‑site confidentiality and integrity.

Affected Systems

All Windows installations of Google Chrome running a version earlier than 150.0.7871.47 are affected. Based on the description, it appears that no equivalent problem is documented for macOS or Linux distributions.

Risk and Exploitability

The CVSS score is 6.5, indicating moderate severity, while the EPSS score of <1% shows a very low probability of widespread exploitation. Although the vulnerability is not listed in CISA’s KEV, the breach of site isolation could grant an attacker unauthorized access to multiple sites and browser processes. Based on the description, the likely attack vector is remote: the attacker delivers a malicious HTML page that triggers user visits a crafted web page.

Generated by OpenCVE AI on July 15, 2026 at 23:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 150.0.7871.47 or later to eliminate the improper access control flaw (CWE‑602).
  • Apply an organization‑wide Chrome policy that blocks or tightly restricts automatic loading of external media content, thereby limiting the window for the flaw to be abused.
  • Configure a strict Content Security Policy that disallows mixed content, mitigating potential exploitation paths.

Generated by OpenCVE AI on July 15, 2026 at 23:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Thu, 16 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
Title Chrome Media Component Policy Bug Enables Site Isolation Bypass on Windows

Tue, 14 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Remote Site Isolation Bypass via Crafted HTML in Chrome Media

Mon, 13 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title Remote Site Isolation Bypass via Crafted HTML in Chrome Media

Sat, 11 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Chrome Media Policy Flaw Allows Site Isolation Bypass on Windows

Thu, 09 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Title Chrome Media Policy Flaw Allows Site Isolation Bypass on Windows

Wed, 08 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Media Component Site Isolation Bypass via Crafted HTML in Chrome on Windows

Tue, 07 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title Media Component Site Isolation Bypass via Crafted HTML in Chrome on Windows

Mon, 06 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Site Isolation Bypass via Media Policy Enforcement Flaw in Windows Chrome

Mon, 06 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Site Isolation Bypass via Media Policy Enforcement Flaw in Windows Chrome

Sun, 05 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Chrome Windows Media Policy Bypass Enables Site Isolation Breach

Sat, 04 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title Chrome Windows Media Policy Bypass Enables Site Isolation Breach

Sat, 04 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Title Site isolation bypass in Google Chrome on Windows

Fri, 03 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Site isolation bypass in Google Chrome on Windows

Fri, 03 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Title Chrome Media Site Isolation Bypass via Crafted HTML

Fri, 03 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Title Chrome Media Site Isolation Bypass via Crafted HTML

Thu, 02 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Title Chrome Site Isolation Bypass via Crafted HTML on Windows

Thu, 02 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Chrome Site Isolation Bypass via Crafted HTML on Windows

Wed, 01 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Title Site Isolation Bypass via Crafted HTML in Google Chrome for Windows

Wed, 01 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Title Site Isolation Bypass via Crafted HTML in Google Chrome for Windows

Wed, 01 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-602
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Site Isolation Bypass via Crafted Media Policy in Chrome
Weaknesses CWE-285

Wed, 01 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Title Site Isolation Bypass via Crafted Media Policy in Chrome
Weaknesses CWE-285

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Insufficient policy enforcement in Media in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Low)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T13:33:38.943Z

Reserved: 2026-06-29T23:11:28.356Z

Link: CVE-2026-14033

cve-icon Vulnrichment

Updated: 2026-07-01T13:33:27.541Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-15T23:45:16Z

Weaknesses
  • CWE-602

    Client-Side Enforcement of Server-Side Security