Google’s Site Isolation architecture was designed to limit the impact of renderer compromise by placing different sites into separate sandboxed processes and preventing most cross-site data from reaching the wrong renderer. The defense was rolled out broadly across desktop Chrome and later expanded to cover additional scenarios including compromised renderers, extension isolation, and selected Android use cases, adding protection beyond the Same Origin Policy and Chrome’s existing sandbox against threats such as UXSS and side-channel attacks including Spectre.
Researchers later showed that a browser-process use-after-free in Chrome’s InstalledAppProvider Mojo interface, tracked as Issue 1062091, could let an attacker with a compromised renderer escape that sandbox entirely. The flaw stemmed from a stale RenderFrameHost pointer retained after destruction, and the published exploit demonstrated a reliable path to browser-process code execution and an unsandboxed renderer by appending --no-sandbox to Chrome’s command line; Chromium-based Microsoft Edge was also affected, and the bug was reachable on desktop systems in Chrome Stable 81 before being moved behind an experimental flag in Chrome 82.

See affected versions and whether adversaries are exploiting it.
8 events from the most recent confirmed update back to the earliest known activity.
Theori said the vulnerable functionality tied to Issue 1062091 was later moved behind an experimental flag in Chrome 82.0.4065.0, limiting its exposure after being reachable in Chrome Stable 81 on desktop.
Theori reported that the Chrome browser-process use-after-free tracked as Issue 1062091 was introduced in Chrome 81.0.4041.0, creating a sandbox-escape condition via InstalledAppProvider.
Theori published technical details for exploiting Issue 1062091, a browser-process use-after-free in Chrome's InstalledAppProvider Mojo interface that allows a compromised renderer to escape the sandbox. The write-up noted Chromium-based Microsoft Edge was also affected.
Chromium further expanded Site Isolation by adding support for <webview> in Chrome 110.
Chromium later expanded Site Isolation with extension isolation in Chrome 92, extending process separation protections to browser extensions.
Starting in Chrome 77, Chromium partially enabled Site Isolation on Android devices with at least 2 GB of RAM for logged-in sites.
In Chrome 77, Chromium expanded Site Isolation on desktop to defend against fully compromised renderer processes and universal cross-site scripting attacks.
Chromium enabled Site Isolation by default for all sites on desktop platforms in Chrome 67 as a defense-in-depth measure against browser vulnerabilities, UXSS, and data leaks across sites.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.