Junglewise Threat Intelligence

CVE-2026-10021: Google Chrome improper input validation in USB

CVE-2026-10021 · Severity: info · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's USB interface could allow a malicious website to execute unauthorized code on a user's computer. This occurs when a user visits a specially crafted webpage, potentially leading to a full system compromise or theft of sensitive data. Users should update their browser to the latest version to mitigate this risk.

Technical details

An improper input validation vulnerability (CWE-20) exists in the WebUSB implementation of Google Chrome prior to version 148.0.7778.216. The flaw stems from insufficient validation of untrusted input processed by the USB component. A remote attacker can exploit this by enticing a user to visit a malicious HTML page, leading to arbitrary code execution within the context of the browser process. The vulnerability is rated as Medium severity by Chromium. A fix is available in version 148.0.7778.216 and later.

Affected products

  • Google Chrome Prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Stable channel update released for Windows, Mac, and Linux.
  • 2026-05-28: disclosed: CVE published to the NVD.

References

Related threats