Executive brief
Google Chrome's Media component contains an out of bounds memory read vulnerability that allows a remote attacker who has already compromised the renderer process to read sensitive data outside the browser's security sandbox via a specially crafted HTML page. This bypasses Chrome's sandbox isolation, potentially exposing user data and credentials stored in memory.
Technical details
An out of bounds read vulnerability exists in Google Chrome's Media component in versions prior to 152.0.7977.65. The vulnerability allows an attacker who has achieved code execution in the renderer process to bypass the sandbox and read arbitrary memory outside the sandbox boundaries through a crafted HTML page. While the renderer process is already compromised as a precondition, this bug enables escalation of that compromise to access protected memory regions. The fix is available in Chrome 152.0.7977.65 and later versions.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed