Executive brief
Google Chrome is a widely used web browser. A vulnerability in its video handling component could allow a remote attacker to access sensitive information from the browser's memory. To exploit this, an attacker would first need to compromise the browser's rendering process and then trick a user into visiting a specially crafted website.
Technical details
An uninitialized use vulnerability (CWE-457) exists in the Video component of Google Chrome for Windows. The flaw allows a remote attacker who has already compromised the renderer process to leak potentially sensitive information from process memory by enticing a user to load a crafted HTML page. This vulnerability is part of a multi-stage attack chain requiring an initial renderer compromise. The issue was addressed in Google Chrome version 149.0.7827.103 for Windows.
Affected products
- Google Chrome prior to 149.0.7827.103
Timeline
- 2026-06-08: advisory: Google released a stable channel update addressing the issue.
- 2026-06-09: disclosed: NVD published the CVE record.