Executive brief
Google Chrome is a widely used web browser. A vulnerability in how the browser handles user input could allow a malicious website to steal sensitive information from other websites you have open. To exploit this, an attacker would first need to compromise a specific part of the browser's internal processing and then trick a user into visiting a specially crafted webpage.
Technical details
An improper input validation vulnerability (CWE-20) exists in the Input component of Google Chrome. The flaw allows a remote attacker to bypass cross-origin isolation and leak sensitive data from other origins. To successfully exploit this, an attacker must first achieve code execution within a compromised renderer process and then entice a user to visit a malicious HTML page. The vulnerability is addressed in Google Chrome version 148.0.7778.179 for Mac and Windows, and 148.0.7778.178 for Linux.
Affected products
- Google Chrome Prior to 148.0.7778.179
Timeline
- 2026-03-29: other: Reported to Google
- 2026-05-19: patched: Stable channel update released
- 2026-05-20: disclosed: CVE published