CVE-2026-11198
A flaw in Google Chrome’s video codecs lets a remote attacker craft a video file that can escape the browser sandbox and take control of the system. The issue exists in all Chrome versions before 149.0.7827.53 and affects Windows, macOS, and Linux users.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Users of Google Chrome on Windows, macOS, or Linux who have not updated to version 149.0.7827.53 or later.
Real-world impact
An attacker could embed malicious code in a video file, trick a victim into opening it, and then gain full control of the victim’s computer, including data theft, ransomware, or further network attacks.
Why this severity
The CVSS score of 9.6 reflects a network-based attack that requires no user interaction, has low complexity, and gives the attacker complete control over confidentiality, integrity, and availability.
What to do about it
- 01Update Google Chrome to version 149.0.7827.53 or later.
- 02Restart the browser.
NVD-referenced vendor advisory
Timeline
- Jun 4, 2026 · Jun 4, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 23, 2026 · 12d agoAdvisory updatedThe NVD record was last revised.
- Jul 24, 2026 · 11d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- chromereleases.googleblog.com/2026/06/stable-channel-upda…vendor advisory
- issues.chromium.org/issues/504395300permissions required