Description
Insufficient policy enforcement in Navigation in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
Published: 2026-07-08
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Insufficient policy enforcement in the navigation handling component of Google Chrome allowed a malicious actor to craft an HTML page that, when loaded, bypasses the browser’s site isolation protection. Based on the description, it is inferred that the failure undermines the isolation boundaries that normally keep separate web origins from interacting, potentially enabling a user to access sensitive information or execute operations in a context that should be segregated. The underlying weakness reflects a lack of proper policy validation and enforcement, and, based on the description, it is inferred that this can lead to confidentiality and integrity exposures in the browser environment.

Affected Systems

All installations of Google Chrome prior to version 150.0.7871.115 are affected. No additional vendor or product variants are listed.

Risk and Exploitability

The vulnerability has a CVSS score of 4.3. It can be exploited remotely via a specially crafted HTML page served over the network. The attack does not require elevated privileges or local access; it relies solely on the victim's browser rendering a malicious page. EPSS score is less than 1%, indicating a very low exploitation probability, and the CVE is not listed in the CISA KEV catalog, indicating no publicly known exploit at the time of analysis. Based on the description, it is inferred that the potential impact remains significant due to the fundamental nature of site isolation in protecting multiple web contents from one another.

Generated by OpenCVE AI on July 26, 2026 at 16:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Chrome update (150.0.7871.115 or newer) that implements the corrected navigation policy enforcement, addressing the improper authorization weakness identified as CWE-602.
  • Confirm that site isolation is enabled and that no extension or policy overrides disable navigation policy checks, ensuring proper access control.
  • Restart all Chrome processes to load the updated policy and fully restore the site isolation boundaries.

Generated by OpenCVE AI on July 26, 2026 at 16:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4677-1 chromium security update
Debian DSA Debian DSA DSA-6387-1 chromium security update
History

Sun, 26 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title Insufficient Navigation Policy Enforcement Allows Site Isolation Bypass in Chrome

Wed, 22 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Chrome Navigation Policy Bypass Enables Site Isolation Escape

Fri, 17 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
Title Chrome Navigation Policy Bypass Enables Site Isolation Escape

Tue, 14 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Site Isolation Bypass via Navigation Policy Flaw in Google Chrome

Mon, 13 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Site Isolation Bypass via Navigation Policy Flaw in Google Chrome

Sun, 12 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Chrome Site Isolation Bypass via Malicious Navigation

Sat, 11 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Title Chrome Site Isolation Bypass via Malicious Navigation

Fri, 10 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Navigation Policy Enforcement Failure Enabling Site Isolation Bypass in Chrome
Weaknesses CWE-264
CWE-287

Thu, 09 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-602
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Navigation Policy Enforcement Failure Enabling Site Isolation Bypass in Chrome
Weaknesses CWE-264
CWE-287

Thu, 09 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 08 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
Description Insufficient policy enforcement in Navigation in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-09T10:34:12.946Z

Reserved: 2026-07-08T17:07:44.491Z

Link: CVE-2026-15130

cve-icon Vulnrichment

Updated: 2026-07-09T10:34:05.135Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T16:30:06Z

Weaknesses
  • CWE-602

    Client-Side Enforcement of Server-Side Security