Executive brief
Google Chrome is a web browser used by billions of users to access websites and web applications. An improper input validation flaw in Chrome's Media component allows a remote attacker to execute arbitrary code outside the browser's security sandbox by visiting a malicious webpage, potentially leading to complete compromise of the user's system including data theft and installation of malware.
Technical details
This vulnerability is an improper input validation issue in the Media component of Google Chrome prior to version 152.0.7977.65. The flaw allows a remote attacker to bypass the browser's sandbox protection mechanism through a crafted HTML page, achieving arbitrary code execution with the privileges of the browser process. The attack vector is network-based and requires only that a user visit a malicious website; no authentication or user interaction beyond normal browsing is required. The vulnerability was patched in Chrome 152.0.7977.65 and later versions.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Chrome 152.0.7977.65