Executive brief
Google Chrome's media playback component contains improper input validation that could allow an attacker to execute arbitrary code outside the browser's security sandbox by opening a malicious HTML page. This could lead to complete compromise of the user's system, bypassing Chrome's built-in protections and potentially enabling installation of malware or theft of sensitive data.
Technical details
The vulnerability is an improper input validation flaw in Chrome's Media component that allows remote code execution (RCE) outside the sandbox. The attack is triggered by a crafted HTML page served to a victim, requiring no user interaction beyond visiting the page. An attacker can exploit this to achieve arbitrary code execution at the system level, completely bypassing Chrome's sandbox isolation mechanism. The vulnerability affects Chrome versions prior to 152.0.7977.65 and is patched in Chrome 152.0.7977.65 and later.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65