Description
Incorrect authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-08-25
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: Bypass Site Isolation leading to potential data leakage
Action: Apply Patch
AI Analysis

Impact

This vulnerability arises from incorrect authorization checks in the SiteIsolation component of Google Chrome. When an attacker can influence the renderer process, a crafted HTML page can trick the browser into treating content from another origin as if it belonged to the same site. The resulting breach bypasses the intended isolation, exposing data or credentials that should be protected by site boundaries.

Affected Systems

Google Chrome on Windows, macOS, Linux, and Android running any build prior to version 152.0.7977.65. All users of these operating system families must update to the patched release to prevent exploitation.

Risk and Exploitability

The Chromium project rates this issue as Medium. The CVSS score is 3.1, reflecting a low‑to‑medium severity. The EPSS score is 0.00377, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, indicating a moderate current exploitation risk. An attacker would need to have already compromised the renderer process—typically via a malicious web page or script—before delivering the crafted content. Once the renderer is compromised, the SiteIsolation bypass grants the attacker full read/write access to all data belonging to the targeted site.

Generated by OpenCVE AI on August 28, 2026 at 18:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 152.0.7977.65 or later on all affected devices.
  • Enable automatic updates to receive future security patches promptly.
  • Encourage safe browsing practices and, where possible, enforce content‑security policies to limit the impact of compromised renderer processes.

Generated by OpenCVE AI on August 28, 2026 at 18:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Fri, 28 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
Title Site Isolation Bypass in Chrome Permits Data Leakage via Malicious HTML

Fri, 28 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N'}


Wed, 26 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 25 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Title Site Isolation Bypass in Chrome Permits Data Leakage via Malicious HTML

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-863
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-27T19:04:54.408Z

Reserved: 2026-08-25T06:07:07.239Z

Link: CVE-2026-79002

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:17:55.863

Modified: 2026-08-28T14:41:08.473

Link: CVE-2026-79002

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T19:00:11Z

Weaknesses