Executive brief
A security vulnerability in Google Chrome's media handling component could allow a malicious website to bypass the browser's Same Origin Policy. By tricking a user into opening a specially crafted video file, an attacker could potentially access sensitive data from other websites or perform unauthorized actions on the user's behalf. This undermines a fundamental security barrier that prevents different websites from interfering with each other.
Technical details
An inappropriate implementation in the Media component of Google Chrome prior to version 148.0.7778.216 allowed a remote attacker to bypass the Same Origin Policy (SOP). The vulnerability is triggered when the browser processes a specially crafted video file. By exploiting this flaw, an attacker can circumvent the security boundaries that isolate web content, potentially leading to the unauthorized disclosure of sensitive information from other origins. The issue is resolved in Chrome version 148.0.7778.216 and later.
Affected products
- Google Chrome Prior to 148.0.7778.216
Timeline
- 2026-05-27: patched: Stable channel update released for desktop.
- 2026-05-28: disclosed: NVD publication date.