Junglewise Threat Intelligence

CVE-2026-10968: Google Chrome improper input validation in Dawn

CVE-2026-10968 · Severity: info · CVSS 8.8 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in Google Chrome's Dawn component, which handles web graphics. If a user visits a specially crafted malicious website, an attacker who has already partially compromised the browser's rendering process could exploit this flaw to steal sensitive data from other open websites or tabs. This could lead to the exposure of private information, such as login sessions or personal data, across different web domains.

Technical details

An improper input validation vulnerability (CWE-20) exists in the Dawn component of Google Chrome on Windows. Dawn is the underlying implementation of the WebGPU standard. The vulnerability allows a remote attacker to leak cross-origin data if they have already achieved a compromise of the renderer process. By enticing a user to visit a malicious HTML page, the attacker can bypass same-origin policy protections to access data from other origins. This issue was addressed in Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome stable channel update released.
  • 2026-06-04: disclosed: CVE published to NVD.

References

Related threats