Junglewise Threat Intelligence

CVE-2026-10946: Google Chrome heap buffer overflow in Media

CVE-2026-10946 · Severity: info · CVSS 8.8 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in the media processing component of Google Chrome could allow an attacker to execute malicious code on a user's computer. To exploit this, an attacker would need to trick a user into visiting a specially crafted website and performing specific interactions or gestures. If successful, this could lead to a total compromise of the browser session and potentially the underlying system, though the impact is partially mitigated by Chrome's security sandbox.

Technical details

A heap-based buffer overflow (CWE-122) exists in the Media component of Google Chrome. The vulnerability is triggered when a remote attacker convinces a user to engage in specific UI gestures while visiting a maliciously crafted HTML page. This flaw allows the attacker to overflow a heap buffer, potentially leading to arbitrary code execution within the context of the browser's sandbox. Google has addressed this issue in version 149.0.7827.53 for Windows, Mac, and Linux. Security researchers at Google identified the flaw, which is tracked as CVE-2026-10946.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
  • 2026-06-04: disclosed: NVD publication date.

References

Related threats