Current plan is to re-enable post M67 launch via Finch, pending strong enough stability signals on site-isolation.
This is to avoid whiplashing the API on and off if site-isolation doesn't stick.
Also is there a site isolation enablement ticket that can be linked? I did some searching but there were a lot of results & it was hard for me to filter through them with confidence.
Site isolation enforces a process boundary for origins, which mitigates a certain class of vulnerabilities related to Spectre.
As for timing please see comment #5.
Site Isolation is now on for all desktop platforms, and SharedArrayBuffer is now re-enabled on all channels for those same platforms. When Site Isolation ships on Android, SAB can be re-enabled there too.
Comment 1 by jfb@chromium.org
, Mar 28 2018