Junglewise Threat Intelligence

CVE-2026-10911: Google Chrome improper input validation in Media

CVE-2026-10911 · Severity: info · CVSS 8.8 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome, a widely used web browser, contained a vulnerability in its media handling component. An attacker who has already compromised the browser's rendering process could exploit this flaw to escape the security sandbox. This would allow the attacker to gain broader access to the underlying operating system, potentially leading to full system compromise or unauthorized data access.

Technical details

A vulnerability exists in the Media component of Google Chrome due to insufficient validation of untrusted input. The flaw is reachable via a crafted HTML page. While the primary attack vector requires the attacker to have already compromised the renderer process (a 'chained' exploit scenario), successful exploitation allows for a sandbox escape. This enables the attacker to execute arbitrary code outside of the restricted browser environment on the host operating system. The issue is addressed in Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-03-24: other: Reported by Google researchers
  • 2026-06-02: patched: Fixed in stable channel update 149.0.7827.53
  • 2026-06-04: disclosed: CVE published

References

Related threats