Executive brief
A security vulnerability in Google Chrome's media processing components could allow an attacker to bypass the browser's security sandbox. This issue occurs when the browser processes specially crafted web content, potentially allowing an attacker who has already compromised a website's tab to gain broader access to the underlying Windows operating system. If successfully exploited, this could lead to unauthorized access to local files or the installation of malicious software.
Technical details
A race condition (CWE-362) exists within the Codecs component of Google Chrome for Windows. The vulnerability is reachable via a crafted HTML page and requires the attacker to have already compromised the renderer process. By exploiting improper synchronization during concurrent execution, a remote attacker can potentially achieve a sandbox escape, moving from the restricted renderer process to the broader system context. This issue was addressed in Chrome version 149.0.7827.53.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-04-17: disclosed: Reported by Google internal researchers
- 2026-06-02: patched: Fixed in stable channel update 149.0.7827.53/54
- 2026-06-04: advisory: NVD publication date