Description
Information leak in MediaCapture in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to potentially leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-01
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch Update
AI Analysis

Impact

The vulnerability occurs in Google Chrome’s MediaCapture component prior to version 152.0.7977.75. A crafted HTML page can trigger the component to expose sensitive information, resulting in an information‑disclosure flaw classified as CWE‑200. The flaw allows a remote attacker to potentially read data from the user’s media devices without authentication or privileged access.

Affected Systems

Affected systems include any Google Chrome installation earlier than 152.0.7977.75 on the stable channel. Users of older Chrome versions, whether on Windows, macOS, or Linux, are susceptible. The issue has been addressed in releases newer than 152.0.7977.75 and is listed in Google’s stable channel update log.

Risk and Exploitability

The CVSS score of 6.5 indicates medium severity. Exploitation requires a user to load a malicious web page that contains a crafted MediaCapture request. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog. As a client‑side remote vulnerability, the primary mitigation is to upgrade Chrome to a patched version and to rely on automatic update mechanisms to receive timely security fixes.

Generated by OpenCVE AI on September 2, 2026 at 14:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 152.0.7977.75 or newer.
  • Enable automatic updates for Chrome to ensure timely patch delivery.
  • If immediate update is not possible, limit media capture by disabling camera permissions for untrusted sites in Chrome settings.

Generated by OpenCVE AI on September 2, 2026 at 14:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Thu, 03 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Wed, 02 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Title Information Leak via MediaCapture in Google Chrome

Wed, 02 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
Title Information Leak via MediaCapture in Google Chrome

Wed, 02 Sep 2026 03:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 02 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
Description Information leak in MediaCapture in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to potentially leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-200
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-02T09:46:30.440Z

Reserved: 2026-09-01T16:21:02.186Z

Link: CVE-2026-84348

cve-icon Vulnrichment

Updated: 2026-09-02T09:46:23.092Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-02T00:18:28.660

Modified: 2026-09-03T17:18:09.980

Link: CVE-2026-84348

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T14:15:06Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor