Browser sandboxing limits what a process handling untrusted web content can do if it is compromised. It reduces the process’s access to files, devices, and other operating-system resources; it does not make browser vulnerabilities or attacks impossible. In Chromium, sandboxing works alongside process separation and, in Chrome, Site Isolation, which further separates sites from one another.
What is browser sandboxing?
Browser sandboxing is a security technique that runs web-content processing with restricted permissions. A page can contain complex, potentially malicious input, so browsers separate some of that work from components with broader access to the operating system.
In Chromium’s architecture, renderer processes handle page content, while the browser process coordinates privileged interactions. A renderer does not need unrestricted direct access to the disk, devices, or other system resources to display a page. The browser can mediate operations that require more authority. This is an example of the design, not a claim that every browser uses identical processes or restrictions.
How does a browser sandbox work?
Separate work and limit permissions
The central principle is least privilege: give each process only the access it needs. Chromium describes renderers as restricted compared with the browser process. If malicious content exploits a renderer vulnerability, the sandbox is intended to limit what the compromised renderer can do next.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minute#1 Best Overall
On Windows, Chromium’s February 2020 explanation describes privilege reduction and operating-system mitigations, with restrictions represented by different sandbox levels. That description is specific to Windows and should not be generalized to other operating systems. Other Chromium platform materials describe additional mechanisms, including mandatory access controls, device filtering, namespaces, and filesystem restrictions. The exact mechanisms vary by platform and process role.
Keep privileged operations under browser control
Because a renderer has limited permissions, it may need the browser process to perform certain privileged operations. This separation helps contain a renderer compromise, but it also means the browser process and some supporting processes can have broader access than renderers. Sandboxing is therefore a layered architecture, not a single switch that makes every browser component equally restricted.
Does browser sandboxing protect my computer?
It can reduce the damage a compromised web-content process can cause. That is a meaningful protection, but it is not a guarantee that a browser exploit cannot escape its sandbox, that privileged components are free of vulnerabilities, or that every attack path is blocked.
Chromium’s threat model explicitly considers renderer compromise and side-channel attacks, including Spectre-like scenarios. The project’s Site Isolation overview reported 10 potentially exploitable renderer-component bugs in M69, 5 in M70, 13 in M71, 13 in M72, and 15 in M73. Chromium said this count included only bugs reported to it or found by its team. These are historical counts from those releases, not a current vulnerability rate or a complete count of bugs.
Sandboxing should be understood as damage limitation within a broader security design. It does not by itself prevent all malware, data theft, phishing, or browser vulnerabilities.
How Site Isolation adds another layer
The Same Origin Policy ordinarily prevents one site from reading another site’s data. But bugs in browser security logic, a compromised renderer, or speculative side channels can threaten that boundary. In Chrome, Site Isolation adds a process-level separation: pages from different sites are placed into separate sandboxed processes so that a process can receive less cross-site data.
Site Isolation and sandboxing address related but distinct risks. The sandbox restricts a process’s operating-system permissions; Site Isolation narrows which sites’ content is handled together in a process. They work alongside the Same Origin Policy rather than replacing it. Chromium describes Site Isolation as an additional defense: “Site Isolation offers an extra line of defense to make such attacks less likely to succeed.”
Chromium’s design document records historical rollout milestones: Site Isolation was enabled by default on desktop for all sites in Chrome 67 and on Android for sites users log into in Chrome 77. Those milestones describe past releases, not current defaults or identical behavior on every device.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallBest Value
What are the limits and tradeoffs?
- It does not eliminate exploits. A sandbox limits a compromised process; it cannot promise that vulnerabilities will not occur or that every exploit will be contained.
- Some processes have broader access. The browser process and some supporting processes need more authority than a renderer, so protections depend on which process is involved.
- Platform details differ. Operating systems expose different restriction mechanisms, and Chromium’s platform-specific descriptions should not be treated as universal browser behavior.
- Site Isolation can use more memory. Chromium identifies increased memory overhead as a tradeoff. The cited material does not establish a current numeric cost; actual impact depends on implementation and device.
Can you check whether Chrome is sandboxed?
Chromium documents the chrome://sandbox page as a diagnostic view, mainly useful to Chromium developers and for troubleshooting. It is not a security product to buy or a setting that explains every browser protection. The page’s details are specific to Chromium-based browsers, and the Windows diagnostic explanation dates to February 2020. For current behavior on a particular device, consult documentation for that browser version and operating system.
Or skip the browser setup
If your goal is to capture a website screenshot rather than configure a local browser, ScreenshotNeo provides a website screenshot API. One GET request returns an image or PDF; its clean-shot flow can accept cookie or consent banners and remove known consent platforms, newsletter popups, and chat widgets before capture. Each of those steps can be turned off. Bot checks, blank pages, timeouts, failed loads, and cache hits cost nothing, and responses identify the page verdict and billing status in headers. ScreenshotNeo also provides an MCP server for AI agents to take screenshots, inspect page information, and capture PDFs.
For example, save a WebP screenshot of a page with cURL:
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
See the ScreenshotNeo API documentation for authentication and request options. One thousand screenshots per month are free with no card; paid plans start at $5 for 3,000. Sign up for ScreenshotNeo.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

