Description
Incomplete cleanup in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-08-25
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: Site isolation bypass via incomplete cleanup in Chrome
Action: Update Chrome
AI Analysis

Impact

An incomplete cleanup in SiteIsolation in Google Chrome versions prior to 152.0.7977.65 enables a remote attacker who has already compromised the renderer process to bypass site isolation by loading a crafted HTML page. The vulnerability does not directly allow arbitrary code execution or privilege escalation, but it removes an important security boundary that isolates sites, potentially allowing a malicious site to interact with resources from another site. The primary weakness is a flaw in the site's isolation cleanup logic (CWE‑459).

Affected Systems

Google Chrome installations on desktop platforms running any version before 152.0.7977.65 are affected. No specific build or platform limitations are indicated beyond the version threshold.

Risk and Exploitability

The CVSS score of 3.1 indicates medium severity in the National Vulnerability Database. The EPSS score is below 1% and the vulnerability is not listed in CISA’s KEV catalog, suggesting limited exploitation evidence. An attacker would still need to obtain a foothold in the renderer process, a non‑trivial prerequisite. Therefore, while the potential impact is significant if the precondition is met, the overall likelihood of exploitation in the wild remains low to moderate pending better exploitation evidence.

Generated by OpenCVE AI on August 28, 2026 at 18:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Chrome update 152.0.7977.65 or later
  • Avoid opening untrusted HTML files that could target renderer processes
  • Consider disabling or limiting site isolation via Chrome command‑line flags

Generated by OpenCVE AI on August 28, 2026 at 18:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Fri, 28 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
Title Site Isolation Bypass via Incomplete Cleanup in Google Chrome

Fri, 28 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N'}


Tue, 25 Aug 2026 23:00:00 +0000

Type Values Removed Values Added
Title Site Isolation Bypass via Incomplete Cleanup in Google Chrome

Tue, 25 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Incomplete cleanup in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-459
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-27T19:04:09.926Z

Reserved: 2026-08-25T06:03:59.078Z

Link: CVE-2026-78903

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:17:47.633

Modified: 2026-08-28T16:00:30.417

Link: CVE-2026-78903

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T19:00:11Z

Weaknesses