Executive brief
Google Chrome is a widely used web browser. A vulnerability in its media processing component could allow a malicious website to execute unauthorized code on a user's computer. While the browser's security sandbox limits the immediate impact, this could be used as a stepping stone for further attacks or to disrupt the user's browsing session.
Technical details
A type confusion vulnerability (CWE-843) exists in the Media component of Google Chrome. The flaw is triggered when the browser processes a specially crafted HTML page, leading to the access of resources using an incompatible type. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious website. Successful exploitation allows for arbitrary code execution within the Chromium renderer sandbox. The issue is resolved in Google Chrome version 149.0.7827.53 for Linux and 149.0.7827.53/.54 for Windows and Mac.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
- 2026-06-04: disclosed: CVE published in NVD