Executive brief
Google Chrome's codec components contain a memory corruption vulnerability that could allow a remote attacker to execute arbitrary code within the browser's sandbox by tricking a user into visiting a specially crafted web page. This could lead to data theft, credential compromise, or further system compromise despite sandbox protections.
Technical details
The vulnerability is a memory corruption issue in Chrome's codec handling components. A remote attacker can exploit this via a crafted HTML page that triggers the vulnerable code path, resulting in arbitrary code execution within the Chrome sandbox. The attack requires no authentication and only requires the user to visit a malicious webpage. While the exploit is sandboxed, it could still enable data theft or further exploitation. The fix is available in Chrome 153.0.8010.36 and later.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched: Chrome 153.0.8010.36 released