Executive brief
Google Chrome is a widely-used web browser that processes media content in web pages. A vulnerability in the Media component's input validation could allow an attacker with a compromised renderer process to escape the security sandbox and execute arbitrary code on the underlying system, potentially compromising user data and system integrity.
Technical details
This vulnerability is an improper input validation flaw in Chrome's Media component that allows sandbox escape. The attack requires the renderer process to be previously compromised; an attacker can then leverage a crafted HTML page to bypass sandbox restrictions and execute arbitrary code with privileges outside the restricted rendering environment. The vulnerability affects Chrome versions prior to 152.0.7977.65 on Windows. Google patched this issue in Chrome 152.0.7977.65, released on August 25, 2026.
Affected products
- Google Chrome prior to 152.0.7977.65 on Windows
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65