Executive brief
Google Chrome is a widely used web browser. A vulnerability in its media handling component could allow a remote attacker to access sensitive information from the computer's memory. This occurs when a user visits a specially crafted website, potentially leading to the exposure of private data from other open tabs or system processes.
Technical details
An information disclosure vulnerability exists in the Media component of Google Chrome due to an inappropriate implementation. A remote, unauthenticated attacker can exploit this by enticing a user to visit a maliciously crafted HTML page. Successful exploitation allows the attacker to read sensitive information from the browser's process memory. This issue is tracked as CWE-269 (Improper Privilege Management) by some sources and has been addressed in Chrome version 149.0.7827.155.
Affected products
- Google Chrome prior to 149.0.7827.155
Timeline
- 2026-05-19: disclosed: Reported by Zhixin Tu
- 2026-06-16: patched: Fixed in Stable Channel Update 149.0.7827.155/.156
- 2026-06-17: advisory: NVD publication date