Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Browser sandboxing limits what a process handling untrusted web content can do if it is compromised. It reduces the process’s access to files, devices, and other operating-system resources; it does not make browser vulnerabilities or attacks impossible. In Chromium, sandboxing works alongside process separation and, in Chrome, Site Isolation, which further separates sites from one another.

What is browser sandboxing?

Browser sandboxing is a security technique that runs web-content processing with restricted permissions. A page can contain complex, potentially malicious input, so browsers separate some of that work from components with broader access to the operating system.

In Chromium’s architecture, renderer processes handle page content, while the browser process coordinates privileged interactions. A renderer does not need unrestricted direct access to the disk, devices, or other system resources to display a page. The browser can mediate operations that require more authority. This is an example of the design, not a claim that every browser uses identical processes or restrictions.

How does a browser sandbox work?

Separate work and limit permissions

The central principle is least privilege: give each process only the access it needs. Chromium describes renderers as restricted compared with the browser process. If malicious content exploits a renderer vulnerability, the sandbox is intended to limit what the compromised renderer can do next.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall

On Windows, Chromium’s February 2020 explanation describes privilege reduction and operating-system mitigations, with restrictions represented by different sandbox levels. That description is specific to Windows and should not be generalized to other operating systems. Other Chromium platform materials describe additional mechanisms, including mandatory access controls, device filtering, namespaces, and filesystem restrictions. The exact mechanisms vary by platform and process role.

Keep privileged operations under browser control

Because a renderer has limited permissions, it may need the browser process to perform certain privileged operations. This separation helps contain a renderer compromise, but it also means the browser process and some supporting processes can have broader access than renderers. Sandboxing is therefore a layered architecture, not a single switch that makes every browser component equally restricted.

Does browser sandboxing protect my computer?

It can reduce the damage a compromised web-content process can cause. That is a meaningful protection, but it is not a guarantee that a browser exploit cannot escape its sandbox, that privileged components are free of vulnerabilities, or that every attack path is blocked.

Chromium’s threat model explicitly considers renderer compromise and side-channel attacks, including Spectre-like scenarios. The project’s Site Isolation overview reported 10 potentially exploitable renderer-component bugs in M69, 5 in M70, 13 in M71, 13 in M72, and 15 in M73. Chromium said this count included only bugs reported to it or found by its team. These are historical counts from those releases, not a current vulnerability rate or a complete count of bugs.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Sandboxing should be understood as damage limitation within a broader security design. It does not by itself prevent all malware, data theft, phishing, or browser vulnerabilities.

How Site Isolation adds another layer

The Same Origin Policy ordinarily prevents one site from reading another site’s data. But bugs in browser security logic, a compromised renderer, or speculative side channels can threaten that boundary. In Chrome, Site Isolation adds a process-level separation: pages from different sites are placed into separate sandboxed processes so that a process can receive less cross-site data.

Site Isolation and sandboxing address related but distinct risks. The sandbox restricts a process’s operating-system permissions; Site Isolation narrows which sites’ content is handled together in a process. They work alongside the Same Origin Policy rather than replacing it. Chromium describes Site Isolation as an additional defense: “Site Isolation offers an extra line of defense to make such attacks less likely to succeed.”

Chromium’s design document records historical rollout milestones: Site Isolation was enabled by default on desktop for all sites in Chrome 67 and on Android for sites users log into in Chrome 77. Those milestones describe past releases, not current defaults or identical behavior on every device.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What are the limits and tradeoffs?

  • It does not eliminate exploits. A sandbox limits a compromised process; it cannot promise that vulnerabilities will not occur or that every exploit will be contained.
  • Some processes have broader access. The browser process and some supporting processes need more authority than a renderer, so protections depend on which process is involved.
  • Platform details differ. Operating systems expose different restriction mechanisms, and Chromium’s platform-specific descriptions should not be treated as universal browser behavior.
  • Site Isolation can use more memory. Chromium identifies increased memory overhead as a tradeoff. The cited material does not establish a current numeric cost; actual impact depends on implementation and device.

Can you check whether Chrome is sandboxed?

Chromium documents the chrome://sandbox page as a diagnostic view, mainly useful to Chromium developers and for troubleshooting. It is not a security product to buy or a setting that explains every browser protection. The page’s details are specific to Chromium-based browsers, and the Windows diagnostic explanation dates to February 2020. For current behavior on a particular device, consult documentation for that browser version and operating system.

Or skip the browser setup

If your goal is to capture a website screenshot rather than configure a local browser, ScreenshotNeo provides a website screenshot API. One GET request returns an image or PDF; its clean-shot flow can accept cookie or consent banners and remove known consent platforms, newsletter popups, and chat widgets before capture. Each of those steps can be turned off. Bot checks, blank pages, timeouts, failed loads, and cache hits cost nothing, and responses identify the page verdict and billing status in headers. ScreenshotNeo also provides an MCP server for AI agents to take screenshots, inspect page information, and capture PDFs.

For example, save a WebP screenshot of a page with cURL:

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

See the ScreenshotNeo API documentation for authentication and request options. One thousand screenshots per month are free with no card; paid plans start at $5 for 3,000. Sign up for ScreenshotNeo.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.