Vulnerability CVE-2026-9979: Information

Description

Insufficient validation of untrusted input in Input in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

Severity: MEDIUM (5.0)
Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L
Published: May 28, 2026
Modified: June 1, 2026
Error type identifier: CWE-20

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
chromiumsisyphus148.0.7778.216-alt1149.0.7827.114-alt1ALT-PU-2026-8548-2419541Fixed

References to Advisories, Solutions, and Tools

    1. cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
      End excluding
      148.0.7778.216

      cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

      cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
      End excluding
      148.0.7778.215

      cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*

      cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*