Impact
An input validation flaw in Chrome Workers allows an attacker who has already compromised a renderer process to craft an HTML page that bypasses site isolation. The vulnerability is a classic example of CWE‑20, insufficient bounds checking or input validation. Because site isolation is designed to keep renderer processes separate, the bypass can let the attacker gain higher privileges and potentially access data or control other tabs that were otherwise isolated. The Chromium team rated the severity of this flaw as high.
Affected Systems
The weakness affects Google Chrome versions that precede the 151.0.7922.109 release. The update published on August 1, 2026 addresses the input validation flaw in Workers, restoring proper site isolation enforcement. Users running Chrome 151.0.7922.108 or earlier are at risk.
Risk and Exploitability
The EPSS score is not currently available, and the vulnerability is not listed in the CISA KEV catalog. However, the flaw has a high internal severity rating and requires that an attacker already has a foothold in the renderer process to create the crafted HTML page. This suggests the attack vector is a local or session-based compromise that escalates via a browser‑level exploit rather than a purely remote attack. The lack of a public EPSS score means the exact likelihood of exploitation cannot be quantified, but the high severity and the nature of the flaw indicate that a motivated attacker could benefit from a quick patch.
OpenCVE Enrichment