Description
Inappropriate implementation in Navigation in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-07-08
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw resides in Chrome’s navigation input handling. A malicious actor can craft an HTML page that the browser processes, allowing the attacker to circumvent the browser’s site isolation boundaries. This bypass is enabled by an input validation weakness (CWE‑20). The Chromium team labels the severity as medium, reflecting that a successful exploit could let an attacker access or execute code across sites that otherwise run in separate renderer processes.

Affected Systems

All installations of Google Chrome prior to version 150.0.7871.115 on any supported operating system are vulnerable, regardless of the platform or deployment environment.

Risk and Exploitability

Use of a crafted page is required to trigger the vulnerability. The EPSS score of <1% indicates a low likelihood of active exploitation, and the CVSS score of 4.3 is not reflected in the CISA KEV catalog. No public exploits have been documented. While the risk is moderate, the potential to compromise data or code from other sites that share a process makes updating a priority for users.

Generated by OpenCVE AI on July 26, 2026 at 16:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 150.0.7871.115 or later
  • Ensure automatic updates are enabled so future patches are applied promptly
  • If an immediate update is not possible, use an alternative browser for sensitive sites

Generated by OpenCVE AI on July 26, 2026 at 16:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4677-1 chromium security update
Debian DSA Debian DSA DSA-6387-1 chromium security update
History

Sun, 26 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title Site Isolation Bypass via Navigation Input Validation in Chrome

Wed, 22 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Navigation Input Validation Allows Site Isolation Bypass in Google Chrome

Thu, 16 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Navigation Input Validation Allows Site Isolation Bypass in Google Chrome

Tue, 14 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Chrome Site Isolation Bypass via Navigation Input Validation

Mon, 13 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Chrome Site Isolation Bypass via Navigation Input Validation

Sat, 11 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Title Site Isolation Bypass via Crafted HTML in Google Chrome

Fri, 10 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Site Isolation Bypass via Crafted HTML in Google Chrome

Fri, 10 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title Site Isolation Bypass via Navigation Handling in Chrome
Weaknesses CWE-264
CWE-284

Thu, 09 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Site Isolation Bypass via Navigation Handling in Chrome
Weaknesses CWE-264
CWE-284

Thu, 09 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 08 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in Navigation in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-09T10:34:51.156Z

Reserved: 2026-07-08T17:07:44.744Z

Link: CVE-2026-15131

cve-icon Vulnrichment

Updated: 2026-07-09T10:34:42.836Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T16:30:06Z

Weaknesses
  • CWE-20

    Improper Input Validation