Executive brief
Google Chrome, a widely used web browser, is affected by a security vulnerability in its video processing components. An attacker could exploit this flaw by tricking a user into opening a specially crafted video file, potentially allowing the attacker to bypass security restrictions that normally isolate the browser from the rest of the computer. This could lead to unauthorized access to the user's system or data.
Technical details
An integer overflow vulnerability exists in the Codecs component of Google Chrome. The flaw is triggered when processing a specially crafted video file, which can lead to memory corruption. A remote, unauthenticated attacker can exploit this by inducing a user to visit a malicious website or open a malicious media file. Successful exploitation could allow the attacker to escape the Chrome sandbox and execute arbitrary code on the underlying host system. The issue is addressed in Chrome version 151.0.7922.72 for Windows and Mac, and 151.0.7922.71 for Linux.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Stable channel update released for desktop
- 2026-07-30: disclosed: NVD publication date