CVE-2026-78953

Executive Summary

CVE-2026-78953 exposes a missing authorization check in Chrome's SiteIsolation feature. A remote attacker who has already compromised the renderer process can craft a malicious PDF to bypass site isolation, potentially accessing data from other sites. The vulnerability is rated Medium severity and is not currently listed in the CISA KEV database.


Authoritative CVE Metadata - CVSS Base Score: 3.1 (LOW) - Published: 2026-08-25T21:17:51.303 - Last Modified: 2026-09-19T14:16:59.297

Original Description: Missing authorization in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted PDF file. (Chromium security severity: Medium)

"The world makes way for the man who knows where he is going."

— Ralph Emerson
Source: NVD