Junglewise Threat Intelligence

CVE-2026-8535: Google Chrome out of bounds read in Media component

CVE-2026-8535 · Severity: medium · CVSS 5.3 · Published 2026-05-14

Technologies: Google Chrome Os, Google Chrome, Linux Kernel, Google ChromeOS. Vendors: Google, Linux.

Executive brief

A security vulnerability in Google Chrome's media handling component could allow an attacker to access sensitive information from the browser's memory. This issue affects users on Linux and ChromeOS who view a specially crafted JPEG image. An exploit could lead to the exposure of private data, though it typically requires the attacker to have already partially compromised a part of the browser's internal processing.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in the Media component of Google Chrome and ChromeOS. The flaw is triggered when processing a specially crafted JPEG file. While the vulnerability is reachable remotely, the advisory notes it specifically allows an attacker who has already compromised the renderer process to read sensitive information from process memory. This could be used to bypass security mitigations like ASLR or to leak user data handled within that process. The issue is resolved in version 148.0.7778.168 and later.

Affected products

  • Google Chrome prior to 148.0.7778.168
  • Google ChromeOS prior to 148.0.7778.168

Timeline

  • 2026-03-23: disclosed: Reported to Chrome by Google internal researchers
  • 2026-05-12: patched: Stable channel update released
  • 2026-05-14: advisory: NVD publication date

References

Related threats