Executive brief
Google Chrome's media processing component contained an uninitialized resource vulnerability that could allow an attacker with control over the renderer process to read sensitive memory outside the sandbox. While requiring a prior compromise of the renderer process, successful exploitation could lead to information disclosure and potential further attacks against the browser's security boundaries.
Technical details
An uninitialized resource vulnerability exists in Google Chrome's Media component prior to version 153.0.8010.36. The vulnerability allows a remote attacker who has already compromised the renderer process to read memory outside the sandbox via a crafted HTML page. This requires an initial compromise of the renderer process as a precondition, but once achieved, permits out-of-bounds memory access. The vulnerability was assigned Chromium security severity "Medium" and is fixed in Chrome 153.0.8010.36 and later versions.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-08: disclosed
- 2026-09-08: patched: Fixed in Chrome 153.0.8010.36