CVE-2026-17686

8.1

Google · Chrome

Google Chrome contains a vulnerability where insufficient input validation in the Passwords component allows a remote attacker to bypass site isolation via a crafted HTML page.

Executive summary

A high severity security flaw in Google Chrome allows remote attackers to bypass site isolation protections, potentially leading to unauthorized data access.

Vulnerability

This vulnerability involves insufficient validation of untrusted input within the Passwords component, which can be triggered by a remote, unauthenticated attacker through a crafted HTML page once the renderer process is compromised.

Business impact

The ability to bypass site isolation poses a significant risk to the confidentiality and integrity of user data stored within the browser. Successful exploitation could allow an attacker to access sensitive information across different origins, potentially leading to credential theft or unauthorized data exfiltration. Given the CVSS score of 8.1, this represents a high risk to organizational security posture.

Remediation

Immediate Action: Update all instances of Google Chrome to version 151.0.7922.72 or later to apply the necessary security patches.

Proactive Monitoring: Monitor browser-related security logs for unusual activity or unexpected cross-origin interactions that may indicate attempted exploitation of site isolation bypasses.

Compensating Controls: Ensure that enterprise security policies enforce the use of up-to-date browsers and consider implementing endpoint protection solutions that can detect malicious renderer process behavior.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

This vulnerability presents a high risk due to its potential to break core browser security boundaries. Organizations should prioritize the deployment of the Chrome update across all managed workstations immediately to ensure users are protected against potential exploitation of this site isolation bypass.

More Google CVEs

Sources