External risk intelligence

Google Chrome Site Isolation Bypass Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.6)

CVE-2026-106237

This vulnerability exists within the Google Chrome browser client. While browsers interact with the internet, this specific flaw requires a user to navigate to a crafted HTML page. It is a client-side application issue, not an internet-facing service, gateway, or appliance, and does not represent a public-facing attack surface in the context of infrastructure or network deployment.

Information Disclosure

Google Chrome

before 155.0.8059.39

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

An information leak vulnerability in Google Chrome could allow a remote attacker to bypass site isolation through a malicious HTML page, though its severity is rated as Low.

  • Website isolation bypass through malicious pages.
  • Focus on confirming relevance and exposure.
  • Understand potential for information exposure.

Attack Path

How an attacker could exploit the issue

An attacker could trick a user into visiting a malicious webpage to bypass security measures in Google Chrome. This bypass could allow them to access sensitive information or perform unauthorized actions, depending on what the vulnerability allows when triggered.

  • No special access required.
  • Visiting a malicious HTML page.
  • Bypasses site isolation, leaks info.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow a malicious website to potentially access information from other websites open in the user's browser, when supported by specific browser configurations.

  • Information from other sites could be exposed.
  • Exposure may occur via a crafted HTML page.
  • Site isolation bypass is the risk.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability affects Google Chrome, a client-side application. The primary responsibility for addressing this likely falls to end-user device management teams or IT operations responsible for deploying and maintaining browsers on endpoints. The first practical step is to identify all endpoints with vulnerable versions of Chrome, confirm user impact, and then coordinate a phased rollout of the update, potentially prioritizing critical user groups or devices.

  • Browser owners should initiate remediation.
  • Verify Chrome browser exposure and reachability.
  • Plan and deploy browser updates.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Google Chrome and how is it used?

Google Chrome is a widely used web browser that acts as the primary interface for users to access the internet. It provides a secure environment for web navigation by isolating different websites from one another, ensuring that data from one site remains private and inaccessible to others. This isolation is a fundamental security feature that protects your session data and personal information while you browse.

What does CWE-200 mean for CVE-2026-106237?

CWE-200 refers to an Information Exposure weakness. In the context of CVE-2026-106237, this means the browser fails to properly restrict access to sensitive information. Specifically, a flaw in how Chrome handles permissions allows a malicious page to bypass security boundaries, potentially leaking data that should be isolated between different websites.

How does an attacker trigger this vulnerability?

An attacker triggers this flaw by luring a user to visit a specifically crafted, malicious HTML page. The vulnerability is not triggered by simply having the browser installed or running in the background. It requires the active engagement of the user to navigate to the attacker's controlled content, which then exploits the browser's permission-handling logic to break out of its intended security isolation.

Do I need to worry about this if I use Chrome internally?

According to Halo Surface Signal, this vulnerability is a client-side browser issue rather than a server-side or gateway concern. While any user navigating to a malicious page is at risk, this does not represent an internet-facing infrastructure flaw. The relevance depends on your users' browsing habits and their likelihood of encountering malicious web content during daily operations.

When should I update my Chrome browser to fix this?

You should prioritize updating Chrome to version 155.0.8059.39 or later as part of your standard maintenance cycle. Because this affects individual endpoints, the first step is to identify all devices running older versions. Once identified, coordinate a phased deployment of the browser update to ensure that all managed systems are protected against this information leak bypass.

References