Impact
In Google Chrome, a flaw in the MediaRecording implementation enables a remote attacker to craft a malicious HTML page that causes the browser to leak sensitive data from process memory. This results in information disclosure, potentially exposing private data that would otherwise be protected inside the browser process. The weakness is based on improper handling of memory buffers, classified under CWE-1300 and CWE-201.
Affected Systems
Affected are all users running Google Chrome versions earlier than 151.0.7922.72 on any platform supported by the desktop release channel. The issue was fixed in the 151.0.7922.72 update announced in July 2026.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation at the time of this analysis. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires the victim to load a specially crafted page, which is feasible for a remote attacker controlling a malicious website. Given the remote nature and relatively simple trigger, the risk is moderate but should be mitigated promptly.
OpenCVE Enrichment
Debian DLA
Debian DSA