Executive brief
A vulnerability in Google Chrome's media component could allow a remote attacker to escape the browser's security sandbox. This occurs if an attacker has already compromised the browser's rendering process and lures a user to a specially crafted webpage. A successful exploit could allow the attacker to gain broader access to the underlying Windows operating system, potentially leading to unauthorized data access or system control.
Technical details
An improper input validation vulnerability (CWE-20) exists in the Media component of Google Chrome on Windows. The flaw allows a remote attacker who has already compromised the renderer process to bypass sandbox restrictions via a crafted HTML page. By providing malicious untrusted input that is insufficiently validated, the attacker can escalate privileges from the sandboxed renderer to the browser process or the host operating system. This vulnerability is addressed in Google Chrome version 149.0.7827.53.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
- 2026-06-04: disclosed: CVE-2026-11041 published