MEDIUM

CVE-2026-12450

Google Chrome 2026-06-17 CVSS v3.1
CVSS
6.5

Description

Inappropriate implementation in Media in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

Summary dbcve.org

This is an information disclosure vulnerability in Google Chrome's Media component (versions prior to 149.0.7827.155). A remote attacker can exploit this by tricking a user into visiting a crafted HTML page, allowing the attacker to read potentially sensitive information directly from the process memory space of the Chrome browser.

Mitigation

Update Google Chrome to version 149.0.7827.155 or later. Organizations should deploy the browser update through their standard software distribution mechanisms and verify functionality after patching.

Weakness (CWE)

CWE-269 Improper Privilege Management

EPSS Score

0.18%
Probability of exploitation in next 30 days
8.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE