Executive brief
Google Chrome's GetUserMedia feature had incomplete cleanup logic that could allow an attacker to access cross-origin data. An attacker who already compromised the browser rendering engine and used social engineering to trick a user could exploit this to steal sensitive information from other websites the user visits.
Technical details
This vulnerability stems from incomplete cleanup in Chrome's GetUserMedia implementation, a feature that manages access to webcams, microphones, and other media devices. The vulnerability requires two preconditions: the attacker must first compromise the renderer process (the sandboxed process that executes web content) and then use social engineering to manipulate the user into visiting a crafted HTML page. Once exploited, the attacker can read cross-origin data from other websites. The issue was resolved in Chrome version 153.0.8010.47.
Affected products
- Google Chrome prior to 153.0.8010.47
Timeline
- 2026-09-15: disclosed
- 2026-09-15: patched: Fixed in Chrome 153.0.8010.47