Executive brief
A security vulnerability exists in Google Chrome for Windows that could allow a remote attacker to execute malicious code. The issue occurs when the browser processes a specially crafted video file, potentially compromising the user's system. Users are advised to update to the latest version of Chrome to mitigate this risk.
Technical details
A heap-based buffer overflow (CWE-122) exists in the libyuv library within Google Chrome for Windows. The vulnerability is triggered when the browser processes a maliciously crafted video file. A remote, unauthenticated attacker can exploit this flaw by enticing a user to visit a malicious website or open a malicious video, leading to arbitrary code execution within the browser's sandbox environment. The issue was addressed in Chrome version 150.0.7871.125.
Affected products
- Google Chrome prior to 150.0.7871.125
Timeline
- 2026-05-19: disclosed: Reported by Google internal researchers
- 2026-07-14: patched: Fixed in version 150.0.7871.125 for Windows
- 2026-07-14: advisory