Chrome 77 for Android Gets Google's 'Site Isolation' Feature to Protect Against Spectre-Like Attacks

Google has also upgraded 'Site Isolation' for desktop users to help protect against "significantly stronger attacks" through Chrome 77.

Advertisement
By Jagmeet Singh | Updated: 18 October 2019 14:11 IST
Highlights
  • Google first brought the feature to desktop users through Chrome 67
  • It essentially isolates the browser from rendering content of sites
  • Chrome users on Android can manually expand its scope

Chrome 77 for Android has received 'Site Isolation' for "high-value sites"

Chrome 77 for Android has received the 'Site Isolation' feature that Google initially rolled out to desktop users through Chrome 67 back in July last year. The new feature helps defend users majorly against attacks that could leverage the Spectre vulnerability to gain sensitive data access from a process. Initially, the Site Isolation feature on Android devices is enabled only for "high-value sites" where users log in using a password. The search giant, however, does have the plan to optimise the feature and expand its presence to further enhance security for Chrome users on the Android platform.

As detailed last year, the Site Isolation feature designed to isolate the browser from rendering the content of each website opened on the system and use a dedicated process for every single site. This restricts the sharing of processes between multiple sites and helps avoid attacks driven by vulnerabilities such as Spectre that was disclosed last year.

Advertisement

"We started isolating all sites for desktop users back in Chrome 67, and now we're excited to enable it on Android for sites that users log into in Chrome 77," Google writes in a security-focussed blog post.

The Site Isolation feature uses resources in the background to enhance security on Chrome 77 for Android that was released last month. This, thus, impacts the performance to some extent.

Advertisement

However, Google says unlike its desktop version that isolates all websites, the feature on Android is turned on only for high-value sites that require login details. "This protects sites with sensitive data that users likely care about, such as banks or shopping sites, while allowing process sharing among less critical sites," the company notes in a separate post published on the Chromium blog.

To ensure that the change won't largely impact the performance, Google has enabled the Site Isolation feature only for Android devices that have at least 2GB of RAM. The Chrome team does have plans to expand it to other devices in the future and is working on "allowing website operators to opt in any site to the Site Isolation, without requiring user login". Also, users can opt in to the full Site Isolation experience that is available on desktops by manually enabling the option from "chrome://flags/#enable-site-per-process".

Advertisement

In addition to the arrival of the Site Isolation feature for Android devices, Google has upgraded its presence on desktops to help protect against "significantly stronger attacks" through Chrome 77.

The post on the Chromium blog highlights that current implementation of the Site Isolation feature protects sensitive data from the following compromised renderer processes:

Advertisement
  • Authentication: Cookies and stored passwords can only be accessed by processes locked to the corresponding site.
  • Network data: Site Isolation uses Cross-Origin Read Blocking to filter sensitive resource types (e.g., HTML, XML, JSON, PDF) from a process, even if that process tries to lie to Chrome's network stack about its origin.
  • Resources labelled with a Cross-Origin-Resource-Policy header are also protected.
  • Stored data and permissions: Renderer processes can only access stored data (e.g., localStorage) or permissions (e.g., microphone) based on the process's site lock.
  • Cross-origin messaging: Chrome's browser process can verify the source origin of postMessage and BroadcastChannel messages, preventing the renderer process from lying about who sent the message.

Additionally, Google is in the development to improve the existing compromised renderer protections by adding CSRF defenses and protecting additional data types by default using Cross-Origin Read Blocking. It is also working to remove cases where the planned protections have not yet applied.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement
Popular Mobile Brands
  1. Oppo Find X9 Ultra With 200-Megapixel Periscope Camera Launched Globally
  2. Motorola Edge 70 Pro+ Leaked Renders Hint at Design, Five Colour Options
  3. Poco M8s 5G Debuts Globally With 7,000mAh Battery: See Price, Features
  4. Vivo X300 FE Roundup: Expected Price in India, Specifications
  5. Coinbase Rolls Out Crypto-Backed Loans in the UK as FCA Shapes Rules
  6. Motorola Edge 70 Fusion Review
  7. iPhone 18 May Not Arrive With Hardware Upgrades as Apple Cuts Costs: Report
  8. Oppo Pad 5 Pro With 13,380mAh Battery Debuts Alongside Pad Mini: See Prices
  1. NASA Shuts Down Voyager 1 Instrument to Extend Mission Life in Deep Space
  2. Oppo Enco Clip 2 With Open-Ear Design, Up to 40 Hours Total Battery Life Launched Alongside Oppo Watch X3 Mini
  3. Vivo Y6t Launched With 6,500mAh Battery, Snapdragon 4 Gen 2 SoC: Price, Specifications
  4. OCBC Partners Lion Global Investors and DigiFT to Launch Tokenised Gold Fund With GOLDX Token
  5. Oppo Pad 5 Pro Launched With 13,380mAh Battery, Snapdragon 8 Elite Gen 5 SoC Alongside Oppo Pad Mini: Price, Features
  6. Redmi K90 Max Launched With Dimensity 9500 SoC, 8,550mAh Battery and Active Cooling Fan: Price, Specifications
  7. Oppo Find X9 Ultra Launched With Snapdragon 8 Elite Gen 5 SoC, 200-Megapixel Periscope Camera: Price, Specifications
  8. Oppo Find X9s Pro Launched With 200-Megapixel Cameras, 7,025mAh Battery: Price, Specifications
  9. OnePlus Ace 6 Ultra Geekbench Listing Reveals MediaTek Dimensity 9500 Chip, 16GB RAM
  10. Motorola Edge 70 Pro+ Leaked Renders Hint at Design, Five Colour Options
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.