Junglewise Threat Intelligence

CVE-2026-9980: Google Chrome site isolation bypass in Printing

CVE-2026-9980 · Severity: info · CVSS 8.8 · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability in Google Chrome's printing component could allow an attacker to bypass critical security boundaries. If a user visits a malicious website, an attacker who has already partially compromised the browser's rendering process could use this flaw to access data from other websites or the underlying system. This bypasses 'Site Isolation,' a primary defense mechanism designed to keep data from different websites separate and secure.

Technical details

An improper input validation vulnerability (CWE-20) exists in the Printing component of Google Chrome. The flaw allows a remote attacker who has already achieved code execution within a compromised renderer process to bypass Site Isolation protections. By enticing a user to visit a specially crafted HTML page, the attacker can leverage insufficient validation to break out of the process sandbox or access data across security origins. This vulnerability is mitigated by the requirement of a prior renderer compromise, but it represents a significant failure of a secondary defense layer. The issue is resolved in Chrome version 148.0.7778.216 and later.

Affected products

  • Google Chrome prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Stable channel update released for Desktop
  • 2026-05-28: disclosed: CVE published to NVD

References

Related threats