Executive brief
A security vulnerability in Google Chrome's media handling component could allow an attacker to bypass the browser's security sandbox. Chrome uses a sandbox to isolate web pages from the rest of the computer; a successful exploit could allow a malicious website to gain unauthorized access to the underlying operating system. This could lead to the theft of sensitive files, installation of malware, or full system compromise.
Technical details
A race condition exists in the GetUserMedia implementation within Google Chrome prior to version 150.0.7871.115. The vulnerability allows a remote attacker who has already compromised the renderer process to escalate privileges and perform a sandbox escape. By enticing a user to visit a specially crafted HTML page, the attacker can exploit this timing issue to execute code outside of the restricted browser environment. This issue was resolved in the stable channel update to version 150.0.7871.115 for Windows and Mac, and 150.0.7871.114 for Linux.
Affected products
- Google Chrome prior to 150.0.7871.115
Timeline
- 2026-06-13: disclosed: Reported to Google by internal researchers
- 2026-07-08: patched: Fixed in Chrome version 150.0.7871.115/114
- 2026-07-08: advisory