Executive brief
A vulnerability in the media handling component of Google Chrome on Windows could allow a malicious website to execute unauthorized code. By tricking a user into visiting a specially crafted webpage, an attacker could potentially gain control over the browser's restricted environment (sandbox). This could lead to the compromise of user data or further attacks on the underlying operating system.
Technical details
A use-after-free (UAF) vulnerability exists in the Media component of Google Chrome on Windows. The flaw is triggered when the browser incorrectly manages memory during the processing of media content, allowing a remote attacker to exploit the memory corruption via a specially crafted HTML page. Successful exploitation enables arbitrary code execution within the confines of the Chromium renderer sandbox. The vulnerability is addressed in Google Chrome version 149.0.7827.53 for Windows.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
- 2026-06-04: disclosed: CVE-2026-11060 published