Junglewise Threat Intelligence

CVE-2026-11079: Google Chrome out of bounds write in Codecs

CVE-2026-11079 · Severity: info · CVSS 4.3 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in the way the browser processes video files could allow a remote attacker to cause memory corruption. In practice, this could lead to browser crashes or potentially allow an attacker to disrupt the normal operation of the application if a user views a specially crafted video file.

Technical details

An out-of-bounds (OOB) memory write vulnerability exists in the Codecs component of Google Chrome. The flaw is caused by insufficient validation of untrusted input when processing video files. A remote, unauthenticated attacker can exploit this by enticing a user to open or view a specially crafted video file, leading to memory corruption. This can result in a denial-of-service (browser crash) or potentially more severe memory-related exploits. The issue is resolved in Google Chrome version 149.0.7827.53 for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
  • 2026-06-04: disclosed: CVE published

References

Related threats