Executive brief
A vulnerability in Google Chrome's media processing components could allow a malicious website to bypass security boundaries. If a user visits a specially crafted webpage, an attacker who has already gained limited control over the browser's rendering process could escape the 'sandbox'—a security layer designed to prevent web content from accessing the rest of the computer. This could lead to unauthorized access to the user's files or system.
Technical details
A use-after-free (UAF) vulnerability exists in the Codecs component of Google Chrome for Windows. The flaw is triggered when the browser incorrectly manages memory during the processing of media content. A remote attacker who has already compromised the renderer process can exploit this issue by enticing a user to visit a malicious HTML page. Successful exploitation allows the attacker to perform a sandbox escape, potentially leading to arbitrary code execution on the host operating system. This issue was addressed in Chrome version 149.0.7827.53.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome version 149.0.7827.53 released to stable channel.
- 2026-06-04: disclosed: CVE-2026-11094 published.