Executive brief
Google Chrome's LiveCaption feature, which provides real-time subtitles for media, contains a security flaw. A remote attacker could use malicious network traffic to trigger an out-of-bounds memory access. While the risk is rated as low, it could potentially lead to minor information disclosure or application instability.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in the LiveCaption component of Google Chrome prior to version 149.0.7827.53. The flaw stems from an inappropriate implementation that fails to properly validate memory boundaries when processing specific network traffic. A remote attacker can exploit this by delivering malicious network data to a victim's browser, potentially leading to an out-of-bounds memory access. Google has addressed this issue in the stable channel update for Windows, Mac, and Linux.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Fixed in Chrome version 149.0.7827.53
- 2026-06-05: disclosed: NVD publication date