Executive brief
A vulnerability in Google Chrome's media recording component could allow a malicious website to access sensitive information stored in the browser's memory. This occurs when a user visits a specially crafted webpage, potentially leading to the exposure of private data from other open tabs or browser processes. Google has released an update to address this issue and protect user data.
Technical details
A side-channel information leakage vulnerability (CWE-1300) exists in the MediaRecording component of Google Chrome. The flaw results from an inappropriate implementation that fails to properly isolate or protect physical side channels during media processing. A remote attacker can exploit this by enticing a user to visit a maliciously crafted HTML page, allowing the attacker to read sensitive information from the browser's process memory. This vulnerability is mitigated in Google Chrome version 151.0.7922.72 and later.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in Chrome Stable channel update 151.0.7922.71/.72
- 2026-07-30: disclosed: NVD publication date