Executive brief
A security vulnerability exists in Google Chrome's video handling component on Windows. An attacker could use a specially crafted webpage to bypass the browser's security sandbox, potentially allowing them to execute unauthorized commands on the underlying operating system. This could lead to a full system compromise if the user visits a malicious site.
Technical details
A use-after-free (UAF) vulnerability exists in the Video component of Google Chrome for Windows. The flaw is triggered when the browser incorrectly manages memory during the processing of video content. A remote attacker who has already compromised the renderer process can exploit this issue by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to escape the Chrome sandbox and execute arbitrary code with the privileges of the logged-in user. This issue is resolved in Chrome version 149.0.7827.115.
Affected products
- Google Chrome prior to 149.0.7827.115
Timeline
- 2026-05-29: disclosed: Reported to Chrome by Google researchers.
- 2026-06-11: patched: Fixed in Stable Channel Update 149.0.7827.114/.115.
- 2026-06-11: advisory