Site Isolation
The latest Site Isolation coverage — news, analysis, and updates from the WindowsNews.AI desk.
Google Shields Android Users from Cross-Site Data Theft with Critical Chrome Patch
Google has released Chrome 150.0.7871.47 for Android to plug a security hole that erodes one of the browser’s fiercest defenses against data-stealing attacks. The update fixes CVE-2026-13866, a...
Chrome Extension Flaw Lets Attackers Bypass Site Isolation—Update Now
Chrome Extension Flaw Lets Attackers Bypass Site Isolation—Update Now Google has patched a medium-severity security flaw in Chrome’s extensions framework that could let a determined attacker slip...
Chrome 149 Patch Nixes High-Risk Site Isolation Bypass, CVE-2026-13034
Google has patched a high-severity security flaw in Chrome that allows attackers who have already compromised the renderer process to bypass the browser's critical site isolation defenses. Tracked as...
Critical Chrome Update Seals High-Severity Site Isolation Bypass—Update to 149.0.7827.197 Now
A newly disclosed vulnerability in Google Chrome undermines one of the browser's most critical security defenses, Site Isolation, potentially allowing attackers who have already compromised the...
Google Chrome 149 Patches High-Severity Site Isolation Bypass Vulnerability (CVE-2026-11693)
Google pushed out Chrome 149.0.7827.103 on June 8, 2026, to stamp out a high-severity security hole that let attackers circumvent the browser's Site Isolation defenses after compromising a renderer...
Critical Chrome Vulnerability CVE-2026-11689 Exposes Saved Passwords on Windows: Patch Available
Google has patched a high-severity vulnerability in Chrome’s built-in password manager that could allow attackers to bypass site isolation after compromising the renderer process. The flaw, tracked...
Chrome 149.0.7827.103 Patches High-Severity Codecs Flaw Enabling Cross-Origin Data Leak on Linux
Google has rolled out a fix for a high-severity vulnerability in Chrome that lets attackers steal sensitive data from other websites using nothing more than a weaponized video file. Tracked as...
Critical Chrome Extension Flaw CVE-2026-11658 Patched: Why Windows Users Must Lock Down Extension Policies Now
Google has released an emergency patch for a high-severity input-validation vulnerability in Chrome’s extension subsystem, tracked as CVE-2026-11658, that could allow attackers to bypass security...
Chrome 148 Closes a Site Isolation Bypass – What It Means for Every Windows Browser User
Google disclosed a high-severity Chromium vulnerability on May 6, 2026, that could let an attacker who already has a foothold in the browser’s rendering engine break one of the web’s most...
Chrome 148 Patches CVE-2026-7945 COOP Flaw Bypassing Site Isolation
Google and Microsoft jointly disclosed CVE-2026-7945 on May 6, 2026, a medium-severity vulnerability in Chromium’s handling of the Cross-Origin-Opener-Policy (COOP) that puts site isolation at...
CVE-2026-7966: Update Chrome 148 and Edge 148 Now to Fix Site Isolation Bypass
Google and Microsoft released critical security updates on May 6 and 7, 2026, addressing a high-severity vulnerability in the Chromium engine’s Site Isolation feature. Tracked as CVE-2026-7966, the...
Chrome 148 Patches CVE-2026-7971 ORB Bypass in Site Isolation
Google began pushing Chrome 148.0.7778.96 to Windows users on May 6, 2026, delivering a patch for CVE-2026-7971—a medium-severity flaw that undermines Opaque Response Block (ORB) and could enable...