Executive brief
Google Chrome's media processing component contains a buffer overflow vulnerability that allows a remote attacker to execute arbitrary code within the browser's sandbox by sending a specially crafted HTML page. This could enable attackers to gain unauthorized access to user data or compromise system security through a malicious webpage.
Technical details
A buffer overflow vulnerability exists in the Media component of Google Chrome prior to version 152.0.7977.65. The vulnerability allows a remote attacker to achieve arbitrary code execution within the browser sandbox via a crafted HTML page. No authentication is required; the attack can be triggered through network exposure when a user visits a malicious website. The vulnerability was patched in Chrome 152.0.7977.65/64, and the fix is now available to users through the stable channel update.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65 for Windows/Mac and 152.0.7977.64 for Linux