CVE-2026-10971
A flaw in Google Chrome’s printing feature on Windows lets a remote attacker escape the browser sandbox if they can run code in the renderer process. The bug is triggered by a specially crafted HTML page and can lead to full system compromise. It affects Chrome versions before 149.0.7827.53 on Windows.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Google Chrome on Windows, versions earlier than 149.0.7827.53.
Real-world impact
An attacker who can trick a user into loading a malicious HTML page could break out of the browser sandbox and execute code with the same privileges as the user, potentially taking over the entire computer.
Why this severity
The CVSS score is high because the attack can be launched over the network, requires no special privileges, and gives the attacker full control of the system. The score reflects the ease of exploitation and the severe impact on confidentiality, integrity, and availability.
What to do about it
- 01Upgrade Google Chrome to version 149.0.7827.53 or later.
- 02Restart the browser to ensure the update takes effect.
NVD description
Timeline
- Jun 4, 2026 · Jun 4, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 22, 2026 · 13d agoAdvisory updatedThe NVD record was last revised.
- Jul 23, 2026 · 12d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- chromereleases.googleblog.com/2026/06/stable-channel-upda…release notes
- issues.chromium.org/issues/513005991permissions required