Executive brief
Google Chrome is a widely used web browser. A vulnerability in the way the browser processes video files could allow a remote attacker to bypass security protections (the sandbox) that normally isolate the browser from the rest of the computer. If successfully exploited, this could allow an attacker to gain unauthorized access to the underlying operating system or user data.
Technical details
An out-of-bounds (OOB) write vulnerability (CWE-787) exists in the Codecs component of Google Chrome. The flaw is triggered when the browser processes a specially crafted video file, leading to memory corruption. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious website or open a malicious video file. Successful exploitation could allow the attacker to escape the Chromium sandbox and execute arbitrary code in the context of the OS. The issue is resolved in Chrome version 149.0.7827.53 and later.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
- 2026-06-04: disclosed: CVE-2026-11037 published.