Back to Intelligence

CVE-2026-106237: Chrome Site Isolation Bypass via Permissions Info Leak — Patching and Detection Guide

SA
Security Arsenal Team
October 7, 2026
7 min read

NVD has published CVE-2026-106237, an information leak in the Permissions component of Google Chrome that allows a remote attacker to bypass site isolation simply by luring a victim to a crafted HTML page. While Chromium's own security team rated this flaw Low, NVD's enrichment scored it CVSS 9.6 (CRITICAL) with a NETWORK attack vector — a gap in severity assessment that defenders cannot afford to get lost in. Site isolation is the last line of defense between a malicious page and your users' cross-site data, session tokens, and credentials. When it fails, the blast radius extends to every authenticated session in the browser.

All Chrome builds prior to 155.0.8059.39 are affected. Given Chrome's dominant enterprise footprint, this is a fleet-wide patch event, not a niche fix.

Technical Analysis

What the vulnerability is

CVE-2026-106237 is an information leak in Chrome's Permissions implementation. In practical terms, the flaw allows a crafted HTML page served from an attacker-controlled origin to infer or extract information that the site isolation architecture (SitePerProcess / strict origin isolation) is specifically designed to keep partitioned.

Chrome's site isolation places cross-origin iframes and documents in separate renderer processes so that even a fully compromised renderer cannot read another site's data. A permissions-state leak that crosses that boundary gives an attacker an oracle: the ability to probe state belonging to other origins the victim is authenticated to — the foundation for cross-site data inference, targeted session attacks, and chaining into deeper renderer compromise.

Exploitation profile (defender's view)

AttributeDetail
CVECVE-2026-106237
ComponentPermissions, Google Chrome (Chromium)
Affected versionsAll builds prior to 155.0.8059.39
Attack vectorNetwork — crafted HTML page, no local access required
User interactionVictim must render the malicious page (drive-by, malvertising, phishing link)
NVD CVSS9.6 (CRITICAL)
Chromium severityLow
Exploitation statusNo confirmed in-the-wild exploitation or CISA KEV listing at time of publication; PoC potential is high given the low complexity of delivery

Why the severity discrepancy matters

The Chromium 'Low' rating reflects the bug's impact in isolation — an information disclosure, not RCE. NVD's 9.6 reflects the systemic consequence: site isolation bypass undermines the browser's core security boundary, and such primitives are routinely chained. The 2025–2026 exploit landscape has repeatedly shown info leaks used as stage one of full renderer-to-sandbox-escape chains. Treat this as a priority patch within your standard browser update SLA, not a deferred low.

Delivery vectors to expect

  • Malvertising and compromised ad networks serving crafted HTML
  • Watering-hole pages targeting specific verticals
  • Phishing links rendered in Chrome (including via embedded WebView/Chromium Embedded Framework applications that bundle vulnerable builds)

Do not forget CEF and Electron-based applications — any app embedding a Chromium build prior to 155.0.8059.39 inherits the exposure and typically lags browser patching by weeks.

Detection & Response

Direct runtime detection of a permissions info leak is not practical at the endpoint — the malicious logic executes as in-page JavaScript inside a legitimate renderer. The defensible detection surface is therefore threefold: (1) inventory of vulnerable builds, (2) policy tampering that disables site isolation, and (3) post-exploit renderer behavior.

SIGMA Rules

YAML
---
title: Chrome Launched with Site Isolation Disabled
id: b3f7a1d2-4c8e-4f5a-9d21-7e6c5b4a3210
status: experimental
description: Detects Chrome launched with command-line flags that weaken or disable site isolation. Attackers or malicious tooling may use these flags to neutralize the very boundary CVE-2026-106237 targets, and their presence in an enterprise fleet is almost never legitimate.
references:
  - https://nvd.nist.gov/vuln/detail/CVE-2026-106237
  - https://attack.mitre.org/techniques/T1562/001/
author: Security Arsenal
date: 2026/06/08
tags:
  - attack.defense_evasion
  - attack.t1562.001
logsource:
  category: process_creation
  product: windows
detection:
  selection_img:
    Image|endswith:
      - '\chrome.exe'
      - '\msedge.exe'
  selection_flags:
    CommandLine|contains:
      - '--disable-site-isolation-trials'
      - '--disable-features=SitePerProcess'
      - '--disable-web-security'
      - '--site-per-process=false'
  condition: selection_img and selection_flags
falsepositives:
  - Legacy internal web app compatibility testing in controlled dev environments
level: high
---
title: Chrome Renderer Spawning Unexpected Child Process
id: c8e2b4f6-1a3d-4e7b-8c92-5f4d3a2b1098
status: experimental
description: Detects chrome.exe spawning script interpreters or shells. Renderer-level exploitation chains — including those that begin with an info leak primitive such as CVE-2026-106237 — frequently escalate to command execution. Chrome spawning cmd, PowerShell, wscript, or mshta is a high-fidelity anomaly on end-user systems.
references:
  - https://nvd.nist.gov/vuln/detail/CVE-2026-106237
  - https://attack.mitre.org/techniques/T1059/
author: Security Arsenal
date: 2026/06/08
tags:
  - attack.execution
  - attack.t1059
logsource:
  category: process_creation
  product: windows
detection:
  selection_parent:
    ParentImage|endswith: '\chrome.exe'
  selection_child:
    Image|endswith:
      - '\cmd.exe'
      - '\powershell.exe'
      - '\pwsh.exe'
      - '\wscript.exe'
      - '\cscript.exe'
      - '\mshta.exe'
      - '\rundll32.exe'
  condition: selection_parent and selection_child
falsepositives:
  - Rare: enterprise browser extensions invoking local helpers; baselining recommended before enforcement
level: high

KQL — Microsoft Sentinel / Defender

Hunt vulnerable Chrome builds across the fleet via Defender TVM, then correlate with suspicious renderer behavior.

KQL — Microsoft Sentinel / Defender
// Hunt 1: Endpoints running Chrome builds vulnerable to CVE-2026-106237 (prior to 155.0.8059.39)
DeviceTvmSoftwareInventory
| where SoftwareName has_any ("chrome", "chromium")
| extend ParsedVersion = parse_version(SoftwareVersion)
| where ParsedVersion < parse_version("155.0.8059.39")
| summarize DeviceCount = dcount(DeviceId), Devices = make_set(DeviceName, 20) by SoftwareName, SoftwareVersion
| order by DeviceCount desc
;
// Hunt 2: Chrome spawning child processes consistent with post-exploitation
DeviceProcessEvents
| where InitiatingProcessFileName =~ "chrome.exe"
| where FileName in~ ("cmd.exe","powershell.exe","pwsh.exe","wscript.exe","cscript.exe","mshta.exe","rundll32.exe")
| project Timestamp, DeviceName, AccountName, FileName, ProcessCommandLine, InitiatingProcessCommandLine, SHA256
| order by Timestamp desc
;
// Hunt 3: Chrome launched with site isolation disabled via command line
DeviceProcessEvents
| where FileName in~ ("chrome.exe","msedge.exe")
| where ProcessCommandLine has_any ("--disable-site-isolation-trials","--disable-web-security","--disable-features=SitePerProcess")
| project Timestamp, DeviceName, AccountName, ProcessCommandLine

Velociraptor VQL

Audit installed Chrome versions across the Windows fleet by reading the uninstall registry keys — a reliable source even when the browser is not running.

VQL — Velociraptor
-- Hunt for Chrome installs vulnerable to CVE-2026-106237 (< 155.0.8059.39)
SELECT * FROM foreach(
  row={
    SELECT FullPath FROM glob(
      globs=[
        'HKLM/SOFTWARE/Microsoft/Windows/CurrentVersion/Uninstall/Google Chrome/DisplayVersion',
        'HKLM/SOFTWARE/WOW6432Node/Microsoft/Windows/CurrentVersion/Uninstall/Google Chrome/DisplayVersion',
        'HKCU/SOFTWARE/Microsoft/Windows/CurrentVersion/Uninstall/Google Chrome/DisplayVersion'
      ], accessor='registry')
  },
  query={
    SELECT FullPath AS VersionKey,
           read_file(filename=FullPath, accessor='registry') AS ChromeVersionRaw
    FROM scope()
  })

Remediation & Verification Script

PowerShell
# CVE-2026-106237 - Chrome patch verification and enforcement (run as admin / via RMM)
$TargetVersion = [version]'155.0.8059.39'

# Locate installed Chrome version (machine and user scope)
$keys = @(
  'HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome',
  'HKLM:\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome',
  'HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome'
)
$installed = foreach ($k in $keys) {
  if (Test-Path $k) { (Get-ItemProperty $k).DisplayVersion }
}

if ($installed) {
  $v = [version]($installed | Select-Object -First 1)
  if ($v -lt $TargetVersion) {
    Write-Warning "VULNERABLE: Chrome $v detected (< $TargetVersion). Triggering update..."
    # Chrome auto-update triggers
    & "$env:ProgramFiles(x86)\Google\Update\GoogleUpdate.exe" /ua /installsource scheduler 2>$null
    & "$env:ProgramFiles\Google\Update\GoogleUpdate.exe" /ua /installsource scheduler 2>$null
  } else {
    Write-Output "COMPLIANT: Chrome $v >= $TargetVersion"
  }
} else {
  Write-Output 'Chrome not found on this host.'
}

# Enforce enterprise update policy so drift cannot recur
$pol = 'HKLM:\SOFTWARE\Policies\Google\Update'
if (-not (Test-Path $pol)) { New-Item -Path $pol -Force | Out-Null }
Set-ItemProperty $pol -Name 'AutoUpdateCheckPeriodMinutes' -Value 360 -Type DWord
Set-ItemProperty $pol -Name 'UpdateDefault' -Value 1 -Type DWord   # 1 = always allow updates
Set-ItemProperty $pol -Name 'Update{8A69D345-D564-463C-AFF1-A69D9E530F96}' -Value 1 -Type DWord
Write-Output 'Chrome auto-update policy enforced.'

Remediation

  1. Patch immediately. Update Chrome to 155.0.8059.39 or later across all Windows, macOS, and Linux endpoints. Verify via chrome://settings/help or the inventory hunts above. Do not rely on user-driven restarts — an updated binary is not active until the browser relaunches.
  2. Force relaunch. In enterprise environments, use the Chrome RelaunchNotification / RelaunchNotificationPeriod policies to compel restart within 24–48 hours of an update landing.
  3. Audit embedded Chromium. Inventory Electron apps, CEF-based tools, and kiosk software bundling Chromium builds prior to 155.0.8059.39; these are your highest-drift assets.
  4. Never disable site isolation. Confirm no GPO, MDM profile, or launch flag sets SiteIsolationPolicy, --disable-site-isolation-trials, or --disable-web-security. The Sigma rule above will catch tampering.
  5. Harden delivery paths. Enforce web filtering categories for malvertising and newly registered domains, and ensure EDR tamper protection covers browser process trees.
  6. Track authoritative sources. NVD entry: https://nvd.nist.gov/vuln/detail/CVE-2026-106237 and the corresponding Chrome Stable Channel update post on the Chrome Releases blog. Monitor CISA KEV for addition — browser info leaks are frequent KEV candidates once PoCs circulate.

The window between NVD publication and public PoC for browser primitives of this class is measured in days to weeks. The exploitation requirement — getting a target to render a page — is the easiest delivery problem an attacker can solve. Patch the fleet, force the relaunch, and hunt for the drift.

Related Resources

Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.