Google Chrome WebRTC Untrusted Input Validation Vulnerability on ChromeOS

Vulnerability

A vulnerability exists in Google Chrome's Media component on ChromeOS, prior to version 148.0.7778.216. It allows a remote attacker, who has compromised the renderer process, to access potentially sensitive information from process memory. This exploitation is achieved through a crafted HTML page, taking advantage of insufficient validation of untrusted input.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive information from process memory, potentially allowing for further exploitation or data leakage.

Remediation

Users can update to Google Chrome version 148.0.7778.216 or later to address this vulnerability.

Added: May 28, 2026, 11:28 PM
Updated: May 28, 2026, 11:28 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
2.5
exploitability
3.3
remediation
7.7
relevance
9.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.