Executive brief
A vulnerability in Google Chrome's media handling component could allow a malicious website to access data from other websites. This occurs when a user visits a specially crafted webpage, potentially leading to the unauthorized disclosure of sensitive information across different web domains. Users should update to the latest version of Chrome to mitigate this risk.
Technical details
An inappropriate implementation vulnerability exists within the Media component of Google Chrome. The flaw allows a remote attacker to bypass cross-origin resource sharing (CORS) or similar security boundaries to leak data from a different origin. Exploitation requires a user to navigate to a malicious, attacker-controlled HTML page. This is categorized by Chromium as a Medium severity issue. The vulnerability is addressed in Google Chrome version 149.0.7827.53 for Windows, Mac, and Linux.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Stable channel update released for desktop
- 2026-06-04: disclosed: CVE published to NVD