CVE-2026-12450
Description
Inappropriate implementation in Media in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
Summary dbcve.org
This is an information disclosure vulnerability in Google Chrome's Media component (versions prior to 149.0.7827.155). A remote attacker can exploit this by tricking a user into visiting a crafted HTML page, allowing the attacker to read potentially sensitive information directly from the process memory space of the Chrome browser.
Mitigation
Update Google Chrome to version 149.0.7827.155 or later. Organizations should deploy the browser update through their standard software distribution mechanisms and verify functionality after patching.