Executive brief
A security vulnerability exists in the Google Chrome web browser's media handling component. An attacker could exploit this flaw by tricking a user into visiting a specially crafted website. If successful, this could allow the attacker to crash the browser or potentially execute unauthorized code on the user's computer, compromising personal data and system security.
Technical details
A use-after-free (UAF) vulnerability exists in the Media component of Google Chrome for Windows. The flaw is triggered when the browser incorrectly manages memory during the processing of media content within a crafted HTML page. A remote, unauthenticated attacker can exploit this by inducing a user to visit a malicious website, leading to heap corruption. This could result in a browser crash (denial of service) or potentially arbitrary code execution within the context of the browser process. The issue is addressed in Google Chrome version 149.0.7827.115.
Affected products
- Google Chrome Prior to 149.0.7827.115
Timeline
- 2026-05-18: other: Reported by external researcher
- 2026-06-11: patched: Stable channel update released
- 2026-06-11: disclosed: Public advisory published