Executive brief
Google Chrome, a widely used web browser, was found to have a security flaw in its media processing components. An attacker could exploit this by tricking a user into visiting a specially crafted website, potentially allowing the attacker to read sensitive information from the browser's memory. Users should update to the latest version of Chrome to protect their data and browsing sessions.
Technical details
An out-of-bounds read vulnerability exists in the Codecs component of Google Chrome prior to version 150.0.7871.47. The flaw is triggered when the browser processes specially crafted media content within an HTML page. A remote, unauthenticated attacker can exploit this by inducing a user to visit a malicious website, leading to the disclosure of sensitive information from the browser's process memory. This is classified as CWE-125. Google has addressed this issue in the stable channel update for desktop.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: advisory
- 2026-06-30: patched