CVE-2026-10949
BaseFortify
Publication date: 2026-06-04
Last updated on: 2026-06-05
Assigner: Chrome
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| chrome | 149.0.7827.53 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-122 | A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc(). |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a heap buffer overflow in the Video component of Google Chrome versions prior to 149.0.7827.53. It allows a remote attacker who has already compromised the renderer process to potentially escape the browser's sandbox by using a specially crafted HTML page.
How can this vulnerability impact me? :
If exploited, this vulnerability could allow an attacker to break out of the sandbox environment that normally restricts what the renderer process can do. This could lead to the attacker gaining higher privileges on the system, potentially allowing them to execute arbitrary code or take control of the affected device.