Impact
A flaw in the cleanup logic of GetUserMedia in Google Chrome, prior to version 153.0.8010.47, permits a remote attacker who has already compromised a renderer process to obtain cross‑origin data. The vulnerability stems from incomplete resource handling, which allows the attacker to read data that should remain inaccessible. According to the report, the flaw is classified as Chromium security severity Medium, indicating that the failure could reveal confidential data but does not enable direct code execution or denial of service.
Affected Systems
The affected product is Google Chrome. The vulnerability exists in all Chrome builds prior to version 153.0.8010.47; the exact revision is not listed. Users running older stable channel releases before the 2026 September update are at risk.
Risk and Exploitability
The CVSS score of 3.1 signals a low‑to‑moderate severity. The EPSS score is below 1%, indicating a very low probability of exploitation at the time of this analysis. The vulnerability is not listed in CISA’s KEV catalog, further implying that widespread exploitation has not been observed. The attack flow requires an attacker to first compromise a renderer process and then leverage social engineering to serve a crafted HTML page that abuses the GetUserMedia API, suggesting that defense in depth is necessary to mitigate possible exploitation.
OpenCVE Enrichment