Executive brief
A security vulnerability in the media component of Google Chrome on ChromeOS could allow a remote attacker to access sensitive information from the device's memory. This occurs when a user visits a specially crafted website, potentially leading to the exposure of private data. Users should update their ChromeOS devices to version 148.0.7778.216 or later to mitigate this risk.
Technical details
An improper input validation vulnerability (CWE-20) exists in the Media component of Google Chrome on ChromeOS. The flaw allows a remote attacker who has already compromised the renderer process to bypass memory protections and read sensitive information from process memory. Exploitation is achieved by enticing a user to visit a maliciously crafted HTML page. This vulnerability is rated as High severity by Chromium and was addressed in ChromeOS version 148.0.7778.216.
Affected products
- Google ChromeOS prior to 148.0.7778.216
Timeline
- 2026-05-27: patched: Stable channel update released for desktop and ChromeOS
- 2026-05-28: disclosed: NVD publication date