Junglewise Threat Intelligence

CVE-2026-10998: Google Chrome out of bounds read in Media

CVE-2026-10998 · Severity: info · CVSS 6.5 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's media component could allow an attacker on the same local network to read sensitive information from the browser's memory. This occurs when the browser processes specially crafted network traffic, potentially exposing data from other open tabs or system processes. Users should update to the latest version of Chrome to mitigate this risk.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in the Media component of Google Chrome. The flaw is triggered by insufficient validation of malicious network traffic received from the local network segment. An unauthenticated attacker sharing the same network (adjacent) can exploit this to perform an out-of-bounds memory read, potentially leading to the disclosure of sensitive information from the browser's process memory. The issue is resolved in Google Chrome version 149.0.7827.53 and later.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
  • 2026-06-04: disclosed: CVE published to NVD

References

Related threats