Junglewise Threat Intelligence

CVE-2026-11668: Google Chrome uninitialized use in Codecs

CVE-2026-11668 · Severity: info · Published 2026-06-09

Technologies: Google Chrome, Google ChromeOS. Vendors: Google.

Executive brief

Google Chrome and ChromeOS are affected by a security vulnerability in the way they process video files. An attacker could use a specially crafted video to bypass security boundaries and access sensitive data from other websites or services the user is currently logged into. This could lead to the unauthorized disclosure of personal information or session data.

Technical details

An uninitialized use vulnerability (CWE-457) exists in the Codecs component of Google Chrome and ChromeOS. The flaw is triggered when the browser processes a specially crafted video file. A remote attacker can exploit this to leak cross-origin data, potentially bypassing Same-Origin Policy (SOP) protections. The vulnerability was reported by Google internal researchers and is addressed in Chrome version 149.0.7827.102 for Linux and 149.0.7827.103 for ChromeOS. Attackers require no special privileges, but must entice a user to visit a malicious site or load a malicious video asset.

Affected products

  • Google ChromeOS prior to 149.0.7827.103
  • Google Chrome prior to 149.0.7827.102 (Linux)

Timeline

  • 2026-05-21: disclosed: Reported by Google researchers
  • 2026-06-08: patched: Stable channel update released
  • 2026-06-09: advisory: NVD publication date

References

Related threats