Description
Use after free in Media in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-06-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A use‑after‑free flaw in Chrome’s Media component allows a remote attacker who has already compromised the renderer process to execute arbitrary code inside the browser’s sandbox. The vulnerability is triggered by a specially crafted HTML page, enabling the attacker to run code with the sandboxed renderer’s privileges, which can lead to privilege escalation and total compromise of the host if the sandbox is bypassed.

Affected Systems

Google Chrome browsers running any desktop platform version prior to 149.0.7827.155 are affected. The flaw exists in the stable channel releases and applies to all operating systems where Chrome is installed.

Risk and Exploitability

The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a very low probability of widespread exploitation at present. However, the CVSS severity is High and the attack requires delivery of malicious HTML through the renderer process, suggesting that an attacker could employ phishing or drive‑by‑download techniques. Successful exploitation would grant code execution within the sandbox, potentially enabling more invasive attacks if the sandbox is leveraged.

Generated by OpenCVE AI on June 17, 2026 at 18:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 149.0.7827.155 or later, which contains the fix for the use‑after‑free bug in the Media component.
  • If the update cannot be applied, uninstall the existing Chrome installation and reinstall the latest stable release from Google’s official download site.
  • Enable automatic updates or use enterprise policy to push the latest Chrome version regularly, ensuring the vulnerability is patched promptly.

Generated by OpenCVE AI on June 17, 2026 at 18:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 17 Jun 2026 07:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 17 Jun 2026 05:15:00 +0000

Type Values Removed Values Added
Description Use after free in Media in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-06-17T13:16:35.228Z

Reserved: 2026-06-16T19:38:32.096Z

Link: CVE-2026-12462

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-17T06:45:03Z

Weaknesses