Junglewise Threat Intelligence

CVE-2026-10960: Google Chrome uninitialized use in Codecs

CVE-2026-10960 · Severity: info · CVSS 8.8 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's media processing components could allow a malicious website to bypass the browser's security sandbox. If an attacker has already compromised the browser's rendering process, they could use this flaw to gain broader access to the underlying operating system. This could lead to unauthorized data access or the installation of malicious software on a user's computer.

Technical details

An uninitialized use vulnerability (CWE-457) exists in the Codecs component of Google Chrome. The flaw allows a remote attacker who has already compromised the renderer process to escalate privileges and potentially achieve a sandbox escape. Exploitation is typically achieved by enticing a user to visit a specially crafted HTML page. This vulnerability was addressed in Chrome version 149.0.7827.53 for Windows, Mac, and Linux. Google classifies the severity of this issue as High.

Affected products

  • Google Chrome Prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Fixed in Chrome version 149.0.7827.53
  • 2026-06-04: disclosed: NVD publication date

References

Related threats