Executive brief
Google Chrome's media capture functionality contained a flaw that allowed attackers to potentially extract sensitive information through a specially crafted web page. An attacker could exploit this vulnerability remotely by hosting a malicious website and tricking users into visiting it, risking exposure of user data without requiring any special user interaction beyond normal browsing.
Technical details
An information disclosure vulnerability exists in Google Chrome's MediaCapture component (versions prior to 152.0.7977.75). The vulnerability allows a remote attacker to leak sensitive information by delivering a crafted HTML page to a victim's browser. The attack vector is network-based and does not require prior authentication or special user interaction beyond visiting a compromised or attacker-controlled website. The flaw permits unauthorized access to data that should be protected by Chrome's security model. The vulnerability was patched in Chrome 152.0.7977.75 and later versions.
Affected products
- Google Chrome prior to 152.0.7977.75
Timeline
- 2026-09-02: disclosed
- 2026-09-02: patched: Fixed in Chrome 152.0.7977.75