Information
To further enhance security, Chrome is moving to a more granular process isolation model called Origin Isolation. Previously, Chrome used Site Isolation, which grouped different origins from the same site (for example, a.example.com and b.example.com) into a single renderer process. With Origin Isolation, each individual origin (for example, a.example.com is isolated from b.example.com) will be isolated in its own renderer process. This change strengthens Chrome's security architecture by better aligning process boundaries with the web's fundamental origin-based security model, offering greater protection against potential vulnerabilities within sites. While each individual process will be smaller, this increase in process granularity may lead to higher overall memory and CPU usage. To balance security and performance, Origin Isolation will be enabled by default only on devices with at least 4GB of RAM.
Enforcing this policy strengthens Chrome's security architecture by better aligning process boundaries with the web's fundamental origin-based security model, offering greater protection against potential vulnerabilities within sites. In high-security environments, treating subdomains or separate web entities under a single 'site' umbrella can expose sensitive data to side-channel attacks (like Spectre) or memory-scraping vulnerabilities if one origin is compromised. Explicitly enforcing this policy ensures that enterprise endpoints consistently maintain a robust process boundary security posture.
Solution
To establish the recommended configuration via Group Policy, set the following UI path to Enabled :
Computer Configuration\Policies\Administrative Templates\Google\Google Chrome - Default Settings (users can override)\Enable origin-keyed process isolation by default
Impact:
Enabling this policy forces a stricter sandboxing boundary. Environments may experience an increase in the total count of running Chrome renderer processes, which can increase the browser's total RAM and CPU usage.