NVD has published CVE-2026-106237, an information leak in the Permissions component of Google Chrome that allows a remote attacker to bypass site isolation simply by luring a victim to a crafted HTML page. While Chromium's own security team rated this flaw Low, NVD's enrichment scored it CVSS 9.6 (CRITICAL) with a NETWORK attack vector — a gap in severity assessment that defenders cannot afford to get lost in. Site isolation is the last line of defense between a malicious page and your users' cross-site data, session tokens, and credentials. When it fails, the blast radius extends to every authenticated session in the browser.
All Chrome builds prior to 155.0.8059.39 are affected. Given Chrome's dominant enterprise footprint, this is a fleet-wide patch event, not a niche fix.
Technical Analysis
What the vulnerability is
CVE-2026-106237 is an information leak in Chrome's Permissions implementation. In practical terms, the flaw allows a crafted HTML page served from an attacker-controlled origin to infer or extract information that the site isolation architecture (SitePerProcess / strict origin isolation) is specifically designed to keep partitioned.
Chrome's site isolation places cross-origin iframes and documents in separate renderer processes so that even a fully compromised renderer cannot read another site's data. A permissions-state leak that crosses that boundary gives an attacker an oracle: the ability to probe state belonging to other origins the victim is authenticated to — the foundation for cross-site data inference, targeted session attacks, and chaining into deeper renderer compromise.
Exploitation profile (defender's view)
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-106237 |
| Component | Permissions, Google Chrome (Chromium) |
| Affected versions | All builds prior to 155.0.8059.39 |
| Attack vector | Network — crafted HTML page, no local access required |
| User interaction | Victim must render the malicious page (drive-by, malvertising, phishing link) |
| NVD CVSS | 9.6 (CRITICAL) |
| Chromium severity | Low |
| Exploitation status | No confirmed in-the-wild exploitation or CISA KEV listing at time of publication; PoC potential is high given the low complexity of delivery |
Why the severity discrepancy matters
The Chromium 'Low' rating reflects the bug's impact in isolation — an information disclosure, not RCE. NVD's 9.6 reflects the systemic consequence: site isolation bypass undermines the browser's core security boundary, and such primitives are routinely chained. The 2025–2026 exploit landscape has repeatedly shown info leaks used as stage one of full renderer-to-sandbox-escape chains. Treat this as a priority patch within your standard browser update SLA, not a deferred low.
Delivery vectors to expect
- Malvertising and compromised ad networks serving crafted HTML
- Watering-hole pages targeting specific verticals
- Phishing links rendered in Chrome (including via embedded WebView/Chromium Embedded Framework applications that bundle vulnerable builds)
Do not forget CEF and Electron-based applications — any app embedding a Chromium build prior to 155.0.8059.39 inherits the exposure and typically lags browser patching by weeks.
Detection & Response
Direct runtime detection of a permissions info leak is not practical at the endpoint — the malicious logic executes as in-page JavaScript inside a legitimate renderer. The defensible detection surface is therefore threefold: (1) inventory of vulnerable builds, (2) policy tampering that disables site isolation, and (3) post-exploit renderer behavior.
SIGMA Rules
---
title: Chrome Launched with Site Isolation Disabled
id: b3f7a1d2-4c8e-4f5a-9d21-7e6c5b4a3210
status: experimental
description: Detects Chrome launched with command-line flags that weaken or disable site isolation. Attackers or malicious tooling may use these flags to neutralize the very boundary CVE-2026-106237 targets, and their presence in an enterprise fleet is almost never legitimate.
references:
- https://nvd.nist.gov/vuln/detail/CVE-2026-106237
- https://attack.mitre.org/techniques/T1562/001/
author: Security Arsenal
date: 2026/06/08
tags:
- attack.defense_evasion
- attack.t1562.001
logsource:
category: process_creation
product: windows
detection:
selection_img:
Image|endswith:
- '\chrome.exe'
- '\msedge.exe'
selection_flags:
CommandLine|contains:
- '--disable-site-isolation-trials'
- '--disable-features=SitePerProcess'
- '--disable-web-security'
- '--site-per-process=false'
condition: selection_img and selection_flags
falsepositives:
- Legacy internal web app compatibility testing in controlled dev environments
level: high
---
title: Chrome Renderer Spawning Unexpected Child Process
id: c8e2b4f6-1a3d-4e7b-8c92-5f4d3a2b1098
status: experimental
description: Detects chrome.exe spawning script interpreters or shells. Renderer-level exploitation chains — including those that begin with an info leak primitive such as CVE-2026-106237 — frequently escalate to command execution. Chrome spawning cmd, PowerShell, wscript, or mshta is a high-fidelity anomaly on end-user systems.
references:
- https://nvd.nist.gov/vuln/detail/CVE-2026-106237
- https://attack.mitre.org/techniques/T1059/
author: Security Arsenal
date: 2026/06/08
tags:
- attack.execution
- attack.t1059
logsource:
category: process_creation
product: windows
detection:
selection_parent:
ParentImage|endswith: '\chrome.exe'
selection_child:
Image|endswith:
- '\cmd.exe'
- '\powershell.exe'
- '\pwsh.exe'
- '\wscript.exe'
- '\cscript.exe'
- '\mshta.exe'
- '\rundll32.exe'
condition: selection_parent and selection_child
falsepositives:
- Rare: enterprise browser extensions invoking local helpers; baselining recommended before enforcement
level: high
KQL — Microsoft Sentinel / Defender
Hunt vulnerable Chrome builds across the fleet via Defender TVM, then correlate with suspicious renderer behavior.
// Hunt 1: Endpoints running Chrome builds vulnerable to CVE-2026-106237 (prior to 155.0.8059.39)
DeviceTvmSoftwareInventory
| where SoftwareName has_any ("chrome", "chromium")
| extend ParsedVersion = parse_version(SoftwareVersion)
| where ParsedVersion < parse_version("155.0.8059.39")
| summarize DeviceCount = dcount(DeviceId), Devices = make_set(DeviceName, 20) by SoftwareName, SoftwareVersion
| order by DeviceCount desc
;
// Hunt 2: Chrome spawning child processes consistent with post-exploitation
DeviceProcessEvents
| where InitiatingProcessFileName =~ "chrome.exe"
| where FileName in~ ("cmd.exe","powershell.exe","pwsh.exe","wscript.exe","cscript.exe","mshta.exe","rundll32.exe")
| project Timestamp, DeviceName, AccountName, FileName, ProcessCommandLine, InitiatingProcessCommandLine, SHA256
| order by Timestamp desc
;
// Hunt 3: Chrome launched with site isolation disabled via command line
DeviceProcessEvents
| where FileName in~ ("chrome.exe","msedge.exe")
| where ProcessCommandLine has_any ("--disable-site-isolation-trials","--disable-web-security","--disable-features=SitePerProcess")
| project Timestamp, DeviceName, AccountName, ProcessCommandLine
Velociraptor VQL
Audit installed Chrome versions across the Windows fleet by reading the uninstall registry keys — a reliable source even when the browser is not running.
-- Hunt for Chrome installs vulnerable to CVE-2026-106237 (< 155.0.8059.39)
SELECT * FROM foreach(
row={
SELECT FullPath FROM glob(
globs=[
'HKLM/SOFTWARE/Microsoft/Windows/CurrentVersion/Uninstall/Google Chrome/DisplayVersion',
'HKLM/SOFTWARE/WOW6432Node/Microsoft/Windows/CurrentVersion/Uninstall/Google Chrome/DisplayVersion',
'HKCU/SOFTWARE/Microsoft/Windows/CurrentVersion/Uninstall/Google Chrome/DisplayVersion'
], accessor='registry')
},
query={
SELECT FullPath AS VersionKey,
read_file(filename=FullPath, accessor='registry') AS ChromeVersionRaw
FROM scope()
})
Remediation & Verification Script
# CVE-2026-106237 - Chrome patch verification and enforcement (run as admin / via RMM)
$TargetVersion = [version]'155.0.8059.39'
# Locate installed Chrome version (machine and user scope)
$keys = @(
'HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome',
'HKLM:\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome',
'HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome'
)
$installed = foreach ($k in $keys) {
if (Test-Path $k) { (Get-ItemProperty $k).DisplayVersion }
}
if ($installed) {
$v = [version]($installed | Select-Object -First 1)
if ($v -lt $TargetVersion) {
Write-Warning "VULNERABLE: Chrome $v detected (< $TargetVersion). Triggering update..."
# Chrome auto-update triggers
& "$env:ProgramFiles(x86)\Google\Update\GoogleUpdate.exe" /ua /installsource scheduler 2>$null
& "$env:ProgramFiles\Google\Update\GoogleUpdate.exe" /ua /installsource scheduler 2>$null
} else {
Write-Output "COMPLIANT: Chrome $v >= $TargetVersion"
}
} else {
Write-Output 'Chrome not found on this host.'
}
# Enforce enterprise update policy so drift cannot recur
$pol = 'HKLM:\SOFTWARE\Policies\Google\Update'
if (-not (Test-Path $pol)) { New-Item -Path $pol -Force | Out-Null }
Set-ItemProperty $pol -Name 'AutoUpdateCheckPeriodMinutes' -Value 360 -Type DWord
Set-ItemProperty $pol -Name 'UpdateDefault' -Value 1 -Type DWord # 1 = always allow updates
Set-ItemProperty $pol -Name 'Update{8A69D345-D564-463C-AFF1-A69D9E530F96}' -Value 1 -Type DWord
Write-Output 'Chrome auto-update policy enforced.'
Remediation
- Patch immediately. Update Chrome to 155.0.8059.39 or later across all Windows, macOS, and Linux endpoints. Verify via
chrome://settings/helpor the inventory hunts above. Do not rely on user-driven restarts — an updated binary is not active until the browser relaunches. - Force relaunch. In enterprise environments, use the Chrome
RelaunchNotification/RelaunchNotificationPeriodpolicies to compel restart within 24–48 hours of an update landing. - Audit embedded Chromium. Inventory Electron apps, CEF-based tools, and kiosk software bundling Chromium builds prior to 155.0.8059.39; these are your highest-drift assets.
- Never disable site isolation. Confirm no GPO, MDM profile, or launch flag sets
SiteIsolationPolicy,--disable-site-isolation-trials, or--disable-web-security. The Sigma rule above will catch tampering. - Harden delivery paths. Enforce web filtering categories for malvertising and newly registered domains, and ensure EDR tamper protection covers browser process trees.
- Track authoritative sources. NVD entry: https://nvd.nist.gov/vuln/detail/CVE-2026-106237 and the corresponding Chrome Stable Channel update post on the Chrome Releases blog. Monitor CISA KEV for addition — browser info leaks are frequent KEV candidates once PoCs circulate.
The window between NVD publication and public PoC for browser primitives of this class is measured in days to weeks. The exploitation requirement — getting a target to render a page — is the easiest delivery problem an attacker can solve. Patch the fleet, force the relaunch, and hunt for the drift.
Related Resources
Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.