Executive brief
Google Chrome is a widely used web browser. A vulnerability in its media processing component could allow a remote attacker to execute malicious code on a user's computer if they open a specially crafted file. While the browser's security sandbox limits the immediate impact, such an exploit could be used as a stepping stone for further attacks on the system or to compromise user data.
Technical details
An integer overflow vulnerability exists in the Media component of Google Chrome. The flaw is triggered when the browser processes a maliciously crafted media file, leading to memory corruption. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious website or open a malicious file, resulting in arbitrary code execution within the context of the Chromium sandbox. The vulnerability is tracked as CVE-2026-10986 and was addressed in Chrome version 149.0.7827.53. Google has classified this with a 'High' severity rating.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
- 2026-06-04: disclosed: CVE-2026-10986 published.