CVE-2026-9991
Inappropriate Implementation in Google Chrome Media on Windows Leads to Cross-Origin Data Leak
Publication date: 2026-05-28
Last updated on: 2026-05-28
Assigner: Chrome
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| chrome | to 148.0.7778.216 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an inappropriate implementation in the Media component of Google Chrome on Windows versions prior to 148.0.7778.216. It allows a remote attacker who has already compromised the renderer process to leak cross-origin data by using a specially crafted HTML page.
How can this vulnerability impact me? :
The vulnerability can lead to unauthorized disclosure of sensitive information across different origins in the browser. An attacker who has compromised the renderer process can exploit this flaw to access data from other websites or web applications that the user has open, potentially leading to privacy breaches or data leakage.