Junglewise Threat Intelligence

CVE-2026-10922: Google Chrome same origin policy bypass in DevTools

CVE-2026-10922 · Severity: info · CVSS 8.8 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its developer tools (DevTools) could allow a remote attacker to bypass security boundaries that normally prevent websites from accessing data from other sites. To exploit this, an attacker would need to trick a user into performing specific mouse or keyboard actions, potentially leading to the theft of sensitive information or unauthorized actions on other websites.

Technical details

A vulnerability exists in Google Chrome's DevTools component due to insufficient validation of untrusted input. A remote attacker can exploit this by convincing a user to perform specific UI gestures, which allows the attacker to bypass the Same Origin Policy (SOP) via malicious network traffic. This bypass could enable an attacker to access sensitive data across different origins or execute unauthorized actions in the context of other sites. The issue is addressed in Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-04-03: other: Reported to Chromium project
  • 2026-06-02: patched: Fixed in stable channel update 149.0.7827.53
  • 2026-06-04: disclosed: CVE published

References

Related threats