Junglewise Threat Intelligence

CVE-2026-10971: Google Chrome improper input validation in Printing component

CVE-2026-10971 · Severity: info · CVSS 8.8 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability in Google Chrome's printing component could allow an attacker to bypass the browser's security sandbox. This occurs when a user visits a specially crafted website, potentially allowing an attacker who has already gained limited control over the browser to escalate their access to the underlying Windows operating system. Such an exploit could lead to unauthorized data access or the installation of malicious software on the user's computer.

Technical details

This vulnerability is classified as improper input validation (CWE-20) within the Printing component of Google Chrome for Windows. The flaw allows a remote attacker who has already compromised the renderer process to bypass sandbox restrictions by leveraging a specially crafted HTML page. By providing malicious input that the printing system fails to validate correctly, the attacker can escape the isolated browser environment to execute code with higher privileges on the host system. The issue is resolved in Google Chrome version 149.0.7827.53 and later.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome Stable Channel Update released
  • 2026-06-04: disclosed: CVE published to NVD

References

Related threats