Sceawere

Vulnerability Detail

CVE-2026-102322UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Chrome SiteIsolation Authorization Bypass

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.6
Creation Date
6h ago
Vendor
Google
Product
Chrome
Attack Type
Incorrect Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Incorrect Authorization in SiteIsolation in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.6",
  "pubDate": "2026-10-06T19:17:39.420Z",
  "pubdate": "2026-10-06T19:17:39.420Z",
  "executiveSummary": "This vulnerability involves an incorrect authorization flaw within the SiteIsolation component of Google Chrome, specifically identified prior to version 155.0.8059.39.\nThe vulnerability is classified with a High security severity rating due to the capability for a remote attacker to execute arbitrary code on the host system.\nThe flaw stems from a failure to correctly enforce authorization boundaries, which are critical to the SiteIsolation security architecture designed to prevent cross-site data leakage and process-based attacks.\nBy leveraging a specially crafted HTML page, an unauthenticated remote attacker can bypass existing security controls to achieve arbitrary code execution within the context of the browser.\nThis compromise facilitates unauthorized access to sensitive user data, potential system-wide persistence, and complete browser exploitation.\nGiven the nature of the exploit—requiring only user interaction through a web page—the risk to the end-user base is significant, necessitating immediate patching of the affected browser instances.",
  "technicalDetails": "The vulnerability resides within the SiteIsolation architecture of the Chromium engine, which is tasked with isolating web pages from different sites into separate operating system processes.\nThe root cause is identified as an incorrect authorization check during the process-assignment or resource-request phase, allowing an attacker to circumvent the browser's sandbox enforcement mechanism.\nSiteIsolation is designed to ensure that data belonging to different origins resides in distinct, sandboxed processes, preventing malicious sites from reading sensitive data or executing code across origin boundaries.\nIn this specific instance, a logic flaw exists that permits a crafted HTML document to manipulate the browser's authorization state during document loading or resource retrieval.\nThe attack flow initiates when a victim navigates to a malicious, attacker-controlled HTML page. This page contains scripted elements designed to exploit the authorization deficiency within the SiteIsolation handler.\nUpon interaction, the crafted content triggers an unexpected state in the renderer process, leading to a memory corruption event or a logic error that effectively breaks the isolation barrier.\nOnce the barrier is circumvented, the attacker can influence the browser's execution flow, enabling the injection and subsequent execution of arbitrary code.\nBecause the exploit operates within the renderer process, it benefits from the execution context of the browser, potentially allowing the attacker to bypass certain OS-level protections if the exploit chain includes secondary vulnerabilities like a sandbox escape.\nThe vulnerable component is explicitly tied to the browser's internal SiteIsolation management logic, which governs cross-process communication and access control lists for active documents.\nAffected versions include all Google Chrome releases prior to 155.0.8059.39. Authentication and elevated privileges are not required for exploitation, as the vulnerability is triggered by a standard browsing event.\nThe impact of a successful exploitation is severe, as it grants the attacker the ability to execute arbitrary code with the same privileges as the Chrome process, leading to a total loss of confidentiality, integrity, and availability of the browser session and potentially the local user environment."
}
CVE-2026-102322: Chrome SiteIsolation Authorization Bypass (CRITICAL Severity, CVSS: 9.6) | Sceawere