Executive brief
Google Chrome, a widely used web browser, contained a security vulnerability in its media handling component on Windows. An attacker who has already partially compromised the browser could use this flaw to steal sensitive information from the computer's memory. This could lead to the exposure of private data or credentials while a user is browsing a malicious website.
Technical details
An improper input validation vulnerability (CWE-20) exists in the Media component of Google Chrome on Windows. The flaw allows a remote attacker who has already achieved code execution within the renderer process (a common first step in browser exploitation) to bypass memory protections. By enticing a user to visit a specially crafted HTML page, the attacker can read sensitive data from the process memory. This vulnerability was addressed in version 150.0.7871.125. While CISA-ADP rates this as Medium (5.3), Chromium internal severity classifies it as High.
Affected products
- Google Chrome prior to 150.0.7871.125
Timeline
- 2026-06-18: disclosed: Reported to Google internally
- 2026-07-14: patched: Fixed in Stable Channel Update 150.0.7871.125
- 2026-07-14: advisory