Executive brief
Google Chrome's codec processing component contained an uninitialized memory resource that allowed attackers to read sensitive data from within the browser sandbox by visiting a malicious webpage. This information disclosure could expose user data or assist in bypassing security protections.
Technical details
An uninitialized resource vulnerability in the Codecs component of Google Chrome allows a remote attacker to read memory inside the Chrome sandbox. The vulnerability is triggered via a crafted HTML page and requires only that a user visit a malicious website—no authentication or user interaction beyond normal browsing is required. The attack vector is network-based. An attacker can achieve information disclosure by reading sensitive data from the sandboxed process memory. The vulnerability was patched in Chrome version 153.0.8010.36 and later.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched: Chrome 153.0.8010.36 released