Executive brief
A security vulnerability has been identified in Google Chrome's media processing components. By tricking a user into visiting a specially crafted website, a remote attacker could potentially bypass the browser's security sandbox. This could allow the attacker to gain unauthorized access to the underlying operating system or sensitive user data.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists in the Codecs component of Google Chrome. The flaw is triggered when the browser processes specially crafted media content within an HTML page. A remote, unauthenticated attacker can exploit this by hosting a malicious website and inducing a user to visit it. Successful exploitation could lead to a sandbox escape, allowing the attacker to execute arbitrary code outside of the restricted browser environment. The issue is resolved in Google Chrome version 150.0.7871.186 and later.
Affected products
- Google Chrome prior to 150.0.7871.186
Timeline
- 2026-05-30: other: Reported to Google
- 2026-07-23: patched: Fixed in stable channel update 150.0.7871.186
- 2026-07-23: disclosed