Junglewise Threat Intelligence

CVE-2026-9991: Google Chrome inappropriate implementation in Media

CVE-2026-9991 · Severity: info · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability in Google Chrome's media component could allow a malicious website to access sensitive data from other websites. This occurs if an attacker has already partially compromised the browser's rendering process, potentially leading to the theft of personal information or login sessions. Users are advised to update to the latest version of Chrome to mitigate this risk.

Technical details

An inappropriate implementation in the Media component of Google Chrome for Windows allowed for cross-origin data leakage. The vulnerability requires a pre-existing compromise of the renderer process (a 'sandbox escape' or similar initial foothold is not provided by this bug alone). Once the renderer is compromised, an attacker can bypass Same-Origin Policy (SOP) restrictions to access data from other origins by enticing a user to visit a specially crafted HTML page. This issue was addressed in Chrome version 148.0.7778.216.

Affected products

  • Google Chrome prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Stable channel update released for Windows, Mac, and Linux.
  • 2026-05-28: disclosed: CVE published to the NVD.

References

Related threats