Executive brief
A vulnerability in the media handling component of Google Chrome could allow a malicious website to execute unauthorized code on a user's computer. While the impact is limited by Chrome's security sandbox, an attacker could potentially disrupt the browser or gain a foothold for further attacks. Users are protected by updating to the latest version of the browser.
Technical details
A use-after-free (UAF) vulnerability exists in the Media component of Google Chrome for Windows. The flaw is triggered when the browser incorrectly manages memory during the processing of media content, allowing an attacker to reference memory after it has been freed. By enticing a user to visit a malicious HTML page, a remote attacker can exploit this condition to achieve arbitrary code execution (ACE) within the constraints of the Chromium sandbox. The issue is addressed in Google Chrome version 148.0.7778.216 and later.
Affected products
- Google Chrome prior to 148.0.7778.216
Timeline
- 2026-05-27: patched: Stable channel update released for desktop
- 2026-05-28: disclosed: CVE published to NVD