Junglewise Threat Intelligence

CVE-2026-10917: Google Chrome improper input validation in Media component

CVE-2026-10917 · Severity: info · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability in Google Chrome's media component could allow an attacker to bypass the browser's security sandbox. If an attacker has already compromised the browser's rendering process, they could use this flaw to gain broader access to the underlying operating system. This could lead to unauthorized access to local files, user data, or the installation of malicious software.

Technical details

This vulnerability is classified as improper input validation (CWE-20) within the Media component of Google Chrome. The flaw allows a remote attacker who has already achieved code execution within a compromised renderer process to bypass sandbox restrictions. By enticing a user to visit a specially crafted HTML page, the attacker can exploit the insufficient validation of untrusted input to escape the process isolation and execute commands with the privileges of the browser process. The issue was addressed in Google Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-03-30: other: Reported by Google researchers
  • 2026-06-02: patched: Fixed in stable channel update 149.0.7827.53
  • 2026-06-04: disclosed: Public CVE publication

References

Related threats