Junglewise Threat Intelligence

CVE-2026-10928: Google Chrome script injection in Headless mode

CVE-2026-10928 · Severity: info · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's Headless mode, often used for automated testing and server-side web processing, contains a vulnerability that allows for script injection. By tricking the browser into loading a specially crafted web page, a remote attacker could execute unauthorized code on the underlying system. This could lead to a full system compromise, data theft, or unauthorized access to internal network resources.

Technical details

A script injection vulnerability (CWE-94) exists in the Headless component of Google Chrome. The flaw allows a remote attacker to achieve arbitrary code execution by enticing a user or automated process to load a maliciously crafted HTML page. The vulnerability stems from improper control of code generation within the Headless environment. This issue was addressed in Google Chrome version 149.0.7827.53 for Windows, Mac, and Linux. Access to specific bug details is currently restricted by the vendor to prevent further exploitation until a majority of users have updated.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-04-06: disclosed: Reported to Google internally
  • 2026-06-02: patched: Fixed in stable channel update 149.0.7827.53
  • 2026-06-04: advisory: CVE published to NVD

References

Related threats