Executive brief
Google Chrome is a widely used web browser. A vulnerability in its video processing component (Codecs) allows a remote attacker to potentially crash the browser or execute unauthorized code if a user opens a specially crafted video file. This could lead to the compromise of the user's computer or the theft of sensitive information handled within the browser.
Technical details
An out-of-bounds (OOB) read and write vulnerability exists in the Codecs component of Google Chrome. The flaw is triggered when the browser processes a specially crafted video file, leading to heap corruption. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious website or open a malicious video file. Successful exploitation could allow for arbitrary code execution within the context of the browser's sandbox or a denial-of-service (browser crash). The issue is resolved in Google Chrome version 150.0.7871.115 for Windows and Mac, and 150.0.7871.114 for Linux.
Affected products
- Google Chrome prior to 150.0.7871.115
Timeline
- 2026-06-06: disclosed: Reported by Google internally
- 2026-07-08: patched: Fixed in stable channel update 150.0.7871.114/.115
- 2026-07-08: advisory