Junglewise Threat Intelligence

CVE-2026-10938: Google Chrome site isolation bypass in Input

CVE-2026-10938 · Severity: info · CVSS 8.8 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's input handling could allow an attacker to bypass critical security boundaries. If a user visits a malicious website, an attacker who has already partially compromised the browser's rendering process can escape the 'sandbox' that normally keeps different websites isolated from each other. This could lead to the theft of sensitive data from other open tabs or websites.

Technical details

A vulnerability exists in the Input component of Google Chrome due to inappropriate implementation and insufficient validation of untrusted input. A remote attacker who has already compromised the renderer process can exploit this flaw via a specially crafted HTML page to bypass Site Isolation. Site Isolation is a security feature that ensures pages from different websites are run in separate processes to prevent data leakage. By bypassing this boundary, an attacker can potentially access sensitive information across different origins. The issue is fixed in Google Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-04-14: disclosed: Reported to Chromium project
  • 2026-06-02: patched: Fixed in stable channel update 149.0.7827.53
  • 2026-06-04: advisory: NVD publication date

References

Related threats