Description
Insufficient validation of untrusted input in COOP in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-05-06
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An attacker who has already compromised a Chrome renderer process can craft a malicious HTML page that takes advantage of insufficient validation of the Cross‑Origin-Opener-Policy (COOP) header. The omission in COOP handling allows the attacker to bypass Chrome’s site isolation, potentially exposing data or browser state that should be protected from other origins. This flaw is a classic input validation weakness, identified as CWE‑20.

Affected Systems

The vulnerability applies to any Google Chrome installation that is running a version earlier than 148.0.7778.96. No specific build numbers are listed beyond the fact that the issue exists in all releases preceding the mentioned patch; the affected operating systems are all that run Chrome, as the cpe entries indicate support on Mac OS, Linux, and Windows.

Risk and Exploitability

The CVSS score of 3.1 indicates a low severity, and the EPSS score is not available so the current likelihood of exploitation cannot be quantified. Because the flaw requires an attacker to first compromise the renderer process, the attack surface is limited to environments where such a compromise is feasible, such as machines with malicious extensions or susceptible to exploitation of another vulnerability. The vulnerability is not listed in the CISA KEV catalog, and no widespread exploitation has been reported, but the potential for cross‑origin data leakage warrants attention.

Generated by OpenCVE AI on May 7, 2026 at 01:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 148.0.7778.96 or later, which restores proper COOP validation.
  • If an upgrade cannot be performed immediately, enforce Chrome’s strict site isolation policy through organization‑wide policy settings to mitigate the risk of a COOP bypass.
  • Disable or limit the use of extensions or untrusted web content that could facilitate a renderer compromise, and monitor Chrome logs for abnormal COOP header handling.

Generated by OpenCVE AI on May 7, 2026 at 01:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6250-1 chromium security update
History

Thu, 07 May 2026 01:30:00 +0000

Type Values Removed Values Added
Title Site Isolation Bypass via Insufficient COOP Validation in Google Chrome

Wed, 06 May 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows

Wed, 06 May 2026 22:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 06 May 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 06 May 2026 20:00:00 +0000

Type Values Removed Values Added
Title Site Isolation Bypass via Insufficient COOP Validation in Google Chrome

Wed, 06 May 2026 18:30:00 +0000

Type Values Removed Values Added
Description Insufficient validation of untrusted input in COOP in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-05-06T21:57:26.339Z

Reserved: 2026-05-05T22:59:16.860Z

Link: CVE-2026-7945

cve-icon Vulnrichment

Updated: 2026-05-06T21:41:34.189Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-06T19:16:42.827

Modified: 2026-05-06T23:32:29.287

Link: CVE-2026-7945

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-07T01:15:17Z

Weaknesses