Google Chrome Extensions Site Isolation Bypass Vulnerability

Vulnerability

A vulnerability in Google Chrome Extensions prior to 149.0.7827.103 allowed remote attackers to bypass site isolation. This was achieved by exploiting an inappropriate implementation in the Extensions component, where a compromised renderer process could be manipulated through a crafted HTML page.

Impact

Exploitation of this vulnerability could lead to a site isolation bypass, allowing potentially malicious content to interact with other sites in ways that are normally restricted.

Remediation

Users can update to Google Chrome version 149.0.7827.103 or later to address this vulnerability.

Added: Jun 9, 2026, 12:59 AM
Updated: Jun 9, 2026, 12:59 AM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
0.6
exploitability
3.6
remediation
7.7
relevance
9.4
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.