Junglewise Threat Intelligence

CVE-2026-12026: Google ChromeOS out of bounds read in Video component

CVE-2026-12026 · Severity: info · Published 2026-06-11

Technologies: Google ChromeOS. Vendors: Google.

Executive brief

A security vulnerability in the video processing component of Google Chrome on ChromeOS could allow an attacker to access sensitive information. By tricking a user into visiting a specially crafted website, an attacker who has already partially compromised the browser's internal processes could read data from the system's memory that they should not have access to. This could lead to the exposure of private user data or credentials stored in memory.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in the Video component of Google Chrome on ChromeOS versions prior to 149.0.7827.115. The flaw is exploitable by a remote attacker who has already achieved a compromise of the renderer process. By enticing a user to load a malicious HTML page, the attacker can leverage this vulnerability to read sensitive information from the process memory. This issue was identified by Google internally and has been addressed in the stable channel update to version 149.0.7827.115.

Affected products

  • Google ChromeOS prior to 149.0.7827.115

Timeline

  • 2026-05-28: other: Reported by Google internal researchers
  • 2026-06-11: patched: Fixed in ChromeOS version 149.0.7827.115
  • 2026-06-11: advisory

References

Related threats