Description
Heap buffer overflow in Video in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Published: 2026-06-04
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A heap buffer overflow occurs in the Video component of Google Chrome before version 149.0.7827.53. If an attacker serves a specially crafted HTML page that compels the renderer process to overflow, the overflow can trigger a sandbox escape. This vulnerability is rated high severity by Chromium.

Affected Systems

The vulnerability affects Google Chrome on desktop systems running any stable channel release older than 149.0.7827.53. Versions 149.0.7827.53 and later contain the fix and are not susceptible to the overflow.

Risk and Exploitability

The CVSS score of 8.3 indicates high severity. An EPSS score is not available and the flaw is not listed in the CISA KEV catalog. The attack requires compromise of the renderer process, implying a higher effort. The potential for sandbox escape poses significant risk for users of affected Chrome versions.

Generated by OpenCVE AI on June 5, 2026 at 06:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 149.0.7827.53 or newer via the official release channel.
  • Ensure Chrome’s automatic update feature is enabled to receive future security fixes promptly.
  • If a timely update is not possible, restrict parsing of untrusted web content and consider additional host‑based sandboxing solutions to mitigate potential exploitation.

Generated by OpenCVE AI on June 5, 2026 at 06:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 05 Jun 2026 06:30:00 +0000

Type Values Removed Values Added
Title Heap Buffer Overflow in Chrome Renderer Causing Sandbox Escapes

Fri, 05 Jun 2026 03:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Fri, 05 Jun 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 05 Jun 2026 02:15:00 +0000

Type Values Removed Values Added
Title Heap Buffer Overflow in Chrome Renderer Causing Sandbox Escapes

Thu, 04 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Heap buffer overflow in Video in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-122
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-06-05T01:39:22.282Z

Reserved: 2026-06-04T17:06:13.417Z

Link: CVE-2026-10949

cve-icon Vulnrichment

Updated: 2026-06-05T01:38:10.095Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-06-04T23:16:57.583

Modified: 2026-06-05T15:02:34.977

Link: CVE-2026-10949

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-05T06:15:33Z

Weaknesses