Junglewise Threat Intelligence

CVE-2026-11640: Google Chrome integer overflow in libyuv

CVE-2026-11640 · Severity: info · CVSS 9.8 · Published 2026-06-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A critical vulnerability was found in its libyuv component, which handles video scaling and conversion. If an attacker lures a user to a malicious website, they could potentially bypass the browser's security sandbox, allowing them to gain unauthorized access to the underlying operating system and user data.

Technical details

An integer overflow vulnerability exists in libyuv, a library used by Google Chrome for video processing. The flaw can be triggered by a remote attacker who has already compromised the renderer process, typically through a separate vulnerability. By enticing a user to visit a specially crafted HTML page, the attacker can exploit this overflow to achieve a sandbox escape. This allows the attacker to execute arbitrary code outside of the restricted browser environment on the host system. The vulnerability is addressed in Chrome version 149.0.7827.103.

Affected products

  • Google Chrome prior to 149.0.7827.103

Timeline

  • 2026-05-28: disclosed: Reported by Google researchers
  • 2026-06-08: patched: Fixed in Stable Channel Update 149.0.7827.102/.103
  • 2026-06-09: advisory: NVD publication date

References

Related threats