Junglewise Threat Intelligence

CVE-2026-10912: Google Chrome input validation bypass in Extensions

CVE-2026-10912 · Severity: info · CVSS 8.8 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A security vulnerability in the browser's Extensions component could allow a malicious website to bypass security boundaries that normally keep data from different websites separate. If exploited, this could allow an attacker to access sensitive information or perform unauthorized actions on other websites you have open.

Technical details

A vulnerability exists in the Extensions component of Google Chrome due to insufficient validation of untrusted input. An attacker who has already compromised the renderer process can exploit this flaw via a specially crafted HTML page to bypass the Same Origin Policy (SOP). This bypass allows the attacker to interact with or extract data from origins they should not have access to. The issue is fixed in Google Chrome version 149.0.7827.53 for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-03-26: disclosed: Reported to Chromium by Google researchers
  • 2026-06-02: patched: Fixed in stable channel update 149.0.7827.53
  • 2026-06-04: advisory: NVD publication date

References

Related threats