vulns.co
/
GKData.io MCP

Google Chrome for Developers · 1 min read

Document Isolation Policy: process separation and residual authority

Explains per-document cross-origin isolation as a response to process-level information exposure that logical origin checks alone cannot prevent. Document Isolation Policy allows independently isolated frames while preserving popup communication. Subresource policy either requires explicit sharing permission or removes credentials from relevant cross-origin requests.

Open the reference Architecture GuideReviewed 2026-10-03

How to use this reference

Editorial lesson: separate process confidentiality, resource delivery and application authority in architecture reviews. Isolation does not remove same-origin storage access or asynchronous messaging, so these channels retain their own authorization requirements. Evaluate isolation choices against required embedded-resource and sign-in behavior.

Before reading

  • Browser origins, frames, HTTP resource policies and process isolation

Context and limits

  • Architectural guidance, not an individual vulnerability disclosure or evidence of deployed compromise. Security benefits are the publisher's design claims.
  • The article establishes desktop availability from Chrome 137; its Android rollout intention is not confirmation of present support. Verify relevant browser support separately.
  • Isolated and non-isolated same-origin frames lose synchronous DOM access but retain asynchronous communication and storage sharing. This is not general tenant isolation.

Sources and provenance

  1. Document Isolation Policy: Enable powerful web features with ease Google Chrome for Developers · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot d5550c789111. Open the complete JSON contract.

GitHub snapshot 2026-10-04

d5550c789111 · JSON exports & schemas · CC BY 4.0 content / MIT software