Executive brief
Google Chrome on Windows contains an authorization bypass vulnerability in its Media component that allows a remote attacker with access to a compromised renderer process to circumvent system access restrictions through a specially crafted HTML page. This could enable attackers to escalate privileges or access restricted system resources that should be protected from web content.
Technical details
This is an incorrect authorization vulnerability in the Media component of Google Chrome on Windows, affecting versions prior to 152.0.7977.65. The vulnerability requires an attacker to have already compromised the renderer process, which could be achieved through another vulnerability in Chrome. Once the renderer is compromised, a crafted HTML page can bypass authorization checks intended to prevent access to system-level media functionality. The attack vector is network-based but requires the precondition of renderer compromise. The vulnerability was patched in Chrome 152.0.7977.65/64 for Windows, Mac, and Linux.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65