Google Chrome Site Isolation Bypass Vulnerability in Plugins

Vulnerability

A vulnerability in the Plugins component of Google Chrome, in versions prior to 149.0.7827.103, allowed remote attackers to bypass site isolation. This was achieved through a crafted HTML page that exploited an inappropriate implementation, targeting the renderer process.

Impact

Exploitation of this vulnerability could lead to a site isolation bypass, potentially allowing for cross-site scripting or other attacks that rely on breaking the browser's site isolation security feature.

Remediation

Users can update to Google Chrome version 149.0.7827.103 or later to address this vulnerability.

Added: Jun 9, 2026, 12:27 AM
Updated: Jun 9, 2026, 12:27 AM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
5.0
exploitability
2.3
remediation
7.7
relevance
9.4
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.