Description
Incomplete cleanup in GetUserMedia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-08-25
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Data Exposure via Incomplete GetUserMedia Cleanup
Action: Patch Promptly
AI Analysis

Impact

GetUserMedia in Google Chrome versions prior to 152.0.7977.65 performs incomplete cleanup of media resources. If the renderer process is already compromised, an attacker can supply a malicious HTML page that tricks the renderer into leaking sensitive data, such as captured audio or video, through the still‑alive media stream. The vulnerability is classified as a medium severity event by Chromium, reflecting the potential for confidential information exposure once the attack conditions are met.

Affected Systems

Affected products include the stable channel of Google Chrome on desktop platforms before the 152.0.7977.65 update. Any device running those versions – whether Windows, macOS, or Linux – is susceptible to this flaw. The issue was fixed in the 152.0.7977.65 release, so applied updates eliminate the risk.

Risk and Exploitability

Risk and exploitability are constrained by the need for the attacker to have already subverted the renderer process and to persuade the user to load a crafted page that triggers the residual media stream. The CVSS score of 5.3 indicates medium severity, and the EPSS score of < 1% indicates a low probability of exploitation, while its absence from the CISA KEV catalog suggests no large‑scale exploitation is currently documented. Nonetheless, the CWE‑459 weakness alerts to a non‑trivial likelihood of data leakage if the attack prerequisites are satisfied. Users running unpatched browsers should consider the possibility of social‑engineering attacks that prompt media access.

Generated by OpenCVE AI on August 26, 2026 at 22:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 152.0.7977.65 or newer.
  • If an immediate upgrade is not possible, block or limit camera access for sites that do not explicitly request it, or use a browser extension that restricts GetUserMedia exposure.
  • Train users to recognize and ignore unsolicited requests for media access, especially in contexts where a renderer process may already be compromised.

Generated by OpenCVE AI on August 26, 2026 at 22:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Mon, 31 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Wed, 26 Aug 2026 23:00:00 +0000

Type Values Removed Values Added
Title Incomplete GetUserMedia Cleanup Enables Remote Sensitive Data Exposure

Wed, 26 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 26 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Title Incomplete GetUserMedia Cleanup Enables Remote Sensitive Data Exposure

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Incomplete cleanup in GetUserMedia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-459
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-26T18:38:24.339Z

Reserved: 2026-08-25T06:12:49.626Z

Link: CVE-2026-79265

cve-icon Vulnrichment

Updated: 2026-08-26T18:17:50.792Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:21.107

Modified: 2026-08-31T16:50:50.463

Link: CVE-2026-79265

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T22:45:03Z

Weaknesses