Junglewise Threat Intelligence

CVE-2026-12450: Google Chrome information disclosure in Media

CVE-2026-12450 · Severity: medium · CVSS 6.5 · Published 2026-06-17

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its media handling component could allow a remote attacker to access sensitive information from the computer's memory. This occurs when a user visits a specially crafted website, potentially leading to the exposure of private data from other open tabs or system processes.

Technical details

An information disclosure vulnerability exists in the Media component of Google Chrome due to an inappropriate implementation. A remote, unauthenticated attacker can exploit this by enticing a user to visit a maliciously crafted HTML page. Successful exploitation allows the attacker to read sensitive information from the browser's process memory. This issue is tracked as CWE-269 (Improper Privilege Management) by some sources and has been addressed in Chrome version 149.0.7827.155.

Affected products

  • Google Chrome prior to 149.0.7827.155

Timeline

  • 2026-05-19: disclosed: Reported by Zhixin Tu
  • 2026-06-16: patched: Fixed in Stable Channel Update 149.0.7827.155/.156
  • 2026-06-17: advisory: NVD publication date

References

Related threats