Description
Inappropriate implementation in ORB in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-05-06
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is an inappropriate implementation of the ORB component in Google Chrome versions prior to 148.0.7778.96, a CWE‑269 weakness that allows a remote attacker to bypass the browser’s site isolation boundaries through a specially crafted HTML page. This bypass can enable the attacker to read or manipulate data from sites that should remain isolated, potentially leading to cross‑site data leakage, cookie theft, or privilege escalation within the browser.

Affected Systems

The vulnerability affects Google Chrome desktop browsers on all platforms running any build before 148.0.7778.96. Users of the stable release channel prior to that build are therefore vulnerable; newer releases contain the fix.

Risk and Exploitability

The attack requires a remote malicious web page hosted by the attacker; no special software or network infrastructure is needed on the victim side. The CVSS score of 6.3 indicates medium severity, and the EPSS score is unavailable, while the vulnerability is not listed in CISA KEV. Consequently the likelihood of exploitation is unclear, but the ability to bypass a core security boundary implies a notable risk for users who visit untrusted or mixed‑content sites.

Generated by OpenCVE AI on May 7, 2026 at 03:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 148.0.7778.96 or newer.
  • Ensure that site isolation is enabled in the browser settings.
  • Keep the browser and operating system up to date and monitor release notes for future fixes.

Generated by OpenCVE AI on May 7, 2026 at 03:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6250-1 chromium security update
History

Thu, 07 May 2026 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows

Thu, 07 May 2026 01:30:00 +0000

Type Values Removed Values Added
Title Google Chrome Site Isolation Bypass via ORB Exploit
Weaknesses CWE-285

Wed, 06 May 2026 22:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 06 May 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 06 May 2026 20:45:00 +0000

Type Values Removed Values Added
Title Google Chrome Site Isolation Bypass via ORB Exploit
Weaknesses CWE-285

Wed, 06 May 2026 18:30:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in ORB in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-05-06T21:53:17.821Z

Reserved: 2026-05-05T22:59:23.902Z

Link: CVE-2026-7971

cve-icon Vulnrichment

Updated: 2026-05-06T21:37:57.277Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-06T19:16:47.980

Modified: 2026-05-07T02:01:24.640

Link: CVE-2026-7971

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-07T04:00:14Z

Weaknesses