Executive brief
A vulnerability in Google Chrome's media handling component could allow an attacker to execute unauthorized code on a user's computer. This occurs if a user visits a specially crafted malicious website and the attacker has already partially compromised the browser's rendering process. Successful exploitation could lead to a breach of user data or unauthorized operations within the browser's security sandbox.
Technical details
An improper input validation vulnerability (CWE-20) exists in the Media component of Google Chrome. The flaw allows a remote attacker who has already compromised the renderer process to execute arbitrary code inside the browser's sandbox by convincing a user to load a specially crafted HTML page. This vulnerability is categorized by Chromium as Medium severity and was addressed in version 149.0.7827.53. The attack requires the attacker to have a foothold in the renderer process as a precondition for sandbox escape or code execution within the sandbox environment.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
- 2026-06-04: disclosed: NVD publication date