Executive brief
Google Chrome is a widely used web browser. A vulnerability in its ImageCapture component could allow a remote attacker who has already partially compromised the browser to gain higher-level system privileges. This could potentially allow an attacker to bypass security boundaries and perform unauthorized actions on the user's device via a specially crafted website.
Technical details
A privilege escalation vulnerability exists in the ImageCapture component of Google Chrome. The flaw stems from an inappropriate implementation that can be triggered by a crafted HTML page. An attacker must first achieve code execution within the sandboxed renderer process (a significant precondition) to exploit this vulnerability. Once the renderer is compromised, the attacker can leverage this flaw to escalate privileges within the browser's architecture. The issue is addressed in Google Chrome version 149.0.7827.53.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
- 2026-06-05: disclosed: CVE published in NVD.