Junglewise Threat Intelligence

CVE-2026-79265: Google Chrome incomplete cleanup in GetUserMedia

CVE-2026-79265 · Severity: medium · CVSS 5.3 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's GetUserMedia function (used for accessing cameras and microphones) fails to properly clean up resources. An attacker who has already compromised the browser's renderer process can exploit this flaw through a crafted web page to access sensitive information from the user's device, potentially bypassing privacy protections on camera and microphone data.

Technical details

The vulnerability is an incomplete cleanup flaw in Chrome's GetUserMedia API implementation. An attacker who has achieved renderer process compromise (requiring prior exploitation or social engineering) can craft a malicious HTML page that triggers improper resource cleanup, leading to information disclosure. The attack vector is network-based (via a crafted webpage) and requires the attacker to already control the renderer process. This allows exfiltration of sensitive data related to media device access. The vulnerability was patched in Chrome 152.0.7977.65 released on August 25, 2026.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Chrome 152.0.7977.65

References

Related threats