Executive brief
A vulnerability in Google Chrome's media processing component could allow a remote attacker to execute malicious code on a user's computer. This occurs when the browser processes a specially crafted video file, potentially leading to unauthorized access or system compromise within the browser's security sandbox. Users are protected by updating to the latest version of the Chrome browser.
Technical details
A use-after-free (UAF) vulnerability exists in the Media component of Google Chrome. The flaw is triggered when the browser improperly manages memory during the processing of specially crafted video files. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious website or open a malicious video, leading to arbitrary code execution (ACE) within the Chromium sandbox. Google has addressed this vulnerability in version 149.0.7827.53 for Windows, Mac, and Linux. Chromium developers have assigned this a 'Medium' severity rating.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
- 2026-06-04: disclosed: CVE published.