Junglewise Threat Intelligence

CVE-2026-10966: Google Chrome sandbox escape in Codecs

CVE-2026-10966 · Severity: info · CVSS 8.8 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's video processing component could allow a malicious website to escape the browser's security sandbox. If exploited, an attacker could gain unauthorized access to the underlying operating system and user data by tricking a user into viewing a specially crafted video file. This poses a significant risk to data confidentiality and system integrity.

Technical details

A vulnerability classified as 'Inappropriate Implementation' exists within the Codecs component of Google Chrome. The flaw is rooted in improper input validation (CWE-20) when processing media content. A remote attacker can exploit this by hosting a specially crafted video file on a malicious website; when a user visits the site, the crafted file triggers the vulnerability. Successful exploitation allows the attacker to bypass the Chromium sandbox, potentially leading to arbitrary code execution on the host operating system. Google has addressed this issue in version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
  • 2026-06-04: disclosed: CVE-2026-10966 published.

References

Related threats