Impact
An input validation flaw in Chrome Workers allows an attacker who has already compromised a renderer process to craft an HTML page that bypasses site isolation. The vulnerability is a classic example of CWE‑20, insufficient bounds checking or input validation. Additionally, CWE‑807 indicates improper isolation of renderer processes, which is exploited by the site isolation bypass. Because site isolation is designed to keep renderer processes separate, the bypass can let the attacker gain higher privileges and potentially access data or control other tabs that were otherwise isolated. The Chromium team rated the severity of this flaw as high.
Affected Systems
The weakness affects Google Chrome versions that precede the 151.0.7922.109 release. The update published on August 1, 2026 addresses the input validation flaw in Workers, restoring proper site isolation enforcement. Users running Chrome 151.0.7922.108 or earlier are at risk.
Risk and Exploitability
The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog. However, the flaw has a high internal severity rating and requires that an attacker already has a foothold in the renderer process to create the crafted HTML page. This suggests the attack vector is a local or session-based compromise that escalates via a browser‑level exploit rather than a purely remote attack. The low EPSS score of < 1% indicates a low probability of exploitation, but the high severity and the nature of the flaw still warrant a quick patch.
OpenCVE Enrichment
Debian DLA
Debian DSA