Junglewise Threat Intelligence

CVE-2026-10949: Google Chrome heap buffer overflow in Video

CVE-2026-10949 · Severity: info · CVSS 8.8 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability in Google Chrome's video component could allow a malicious website to bypass the browser's security sandbox. If an attacker has already compromised the part of the browser that displays web pages, they could use this flaw to gain broader access to the underlying computer system. This could lead to the theft of sensitive data or the installation of unauthorized software.

Technical details

A heap buffer overflow vulnerability (CWE-122) exists in the Video component of Google Chrome prior to version 149.0.7827.53. The flaw can be triggered by a crafted HTML page. While the primary attack vector requires the attacker to have already compromised the renderer process (a 'second-stage' exploit), successful exploitation allows for a sandbox escape. This enables the attacker to execute arbitrary code outside of the restricted browser environment on the host operating system. The vulnerability was addressed in the stable channel update for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Fixed in version 149.0.7827.53
  • 2026-06-04: disclosed: NVD publication date

References

Related threats