Junglewise Threat Intelligence

CVE-2026-13858: Google Chrome out of bounds read in FFmpeg

CVE-2026-13858 · Severity: info · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in the FFmpeg component of Google Chrome could allow a remote attacker to access sensitive information from the browser's memory. This occurs when the browser processes a specially crafted video file, potentially leading to the exposure of private data from other open tabs or system processes. Users are advised to update to the latest version of Chrome to mitigate this risk.

Technical details

This vulnerability is classified as an out-of-bounds read (CWE-125) within the FFmpeg multimedia framework as integrated into Google Chrome. The flaw is triggered when the browser attempts to process a maliciously crafted video file, leading the application to read memory outside of the intended buffer. A remote, unauthenticated attacker can exploit this by enticing a user to visit a website hosting the malicious media. Successful exploitation allows the attacker to leak potentially sensitive information from the browser's process memory. The issue was addressed in Chrome version 150.0.7871.47.

Affected products

  • Google Chrome Prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats