Junglewise Threat Intelligence

CVE-2026-11669: Google Chrome on ChromeOS out of bounds read in Media

CVE-2026-11669 · Severity: info · CVSS 0 · Published 2026-06-09

Technologies: Google ChromeOS. Vendors: Google.

Executive brief

A security vulnerability exists in the media handling component of Google Chrome on ChromeOS. This flaw could allow a malicious website to access sensitive information from the browser's memory if the attacker has already partially compromised the browser's rendering process. This could lead to the exposure of private user data or session information.

Technical details

This vulnerability is classified as an out-of-bounds read (and potentially an integer overflow) within the Media component of Google Chrome on ChromeOS. The flaw is reachable by a remote attacker who has already achieved a compromise of the renderer process. By enticing a user to visit a specially crafted HTML page, the attacker can exploit this memory safety issue to read sensitive information from the process memory. The issue was addressed in ChromeOS version 149.0.7827.103. The vulnerability is tracked as CWE-472 (External Control of Assumed-Immutable Web Parameter) in some contexts, though the primary impact is memory disclosure.

Affected products

  • Google ChromeOS prior to 149.0.7827.103

Timeline

  • 2026-05-21: disclosed: Reported to Chromium project
  • 2026-06-08: patched: Fixed in Stable Channel Update 149.0.7827.103
  • 2026-06-09: advisory: NVD publication date

References

Related threats