Junglewise Threat Intelligence

CVE-2026-10983: Google Chrome improper input validation in Dawn

CVE-2026-10983 · Severity: info · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in Google Chrome's Dawn component, which handles graphics processing. By tricking a user into visiting a specially crafted website, a remote attacker could bypass the browser's security sandbox. This could allow the attacker to gain unauthorized access to the underlying operating system or user data, potentially leading to a full system compromise.

Technical details

An improper input validation vulnerability (CWE-20) exists in the Dawn component of Google Chrome. Dawn is the implementation of the WebGPU standard in Chromium. The flaw allows a remote attacker to bypass sandbox restrictions by providing malicious input through a specially crafted HTML page. If successfully exploited, this could lead to a sandbox escape, allowing code execution outside of the browser's restricted environment. The vulnerability is addressed in Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome stable channel update 149.0.7827.53 released
  • 2026-06-04: disclosed: CVE published

References

Related threats