Executive brief
Google Chrome is a widely used web browser. A vulnerability was identified in its video processing library (libyuv) that could allow an attacker to access sensitive information from the computer's memory. This typically occurs if a user visits a specially crafted malicious website, potentially leading to the exposure of private data or further system compromise.
Technical details
An integer overflow vulnerability exists in the libyuv library used by Google Chrome for video scaling and conversion. The flaw is reachable via a crafted HTML page. An attacker who has already compromised the renderer process can exploit this overflow to perform out-of-bounds memory access, allowing them to obtain sensitive information from the process memory. This vulnerability was fixed in Chrome version 149.0.7827.103 for Windows and Mac, and 149.0.7827.102 for Linux. The issue is tracked by Google as a High severity security flaw.
Affected products
- Google Chrome prior to 149.0.7827.103
Timeline
- 2026-05-27: disclosed: Reported to Chromium project by Google researchers
- 2026-06-08: patched: Fixed in stable channel update 149.0.7827.103
- 2026-06-09: advisory: NVD publication date