Back

HIGH

chromium-browser: Google Chrome Codecs: Sandbox escape via crafted HTML page

Published Jul 23, 2026

Description

Out of bounds write in Codecs in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Affected products

Remediation

Red Hat statement

This flaw is rated as Important because a remote attacker could exploit an out-of-bounds write vulnerability in the Codecs component of Google Chrome, or applications embedding Chromium-based web engines, via a specially crafted HTML page. Successful exploitation could lead to a sandbox escape, allowing the attacker to bypass security restrictions and gain unauthorized access to the underlying system.

References (7)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner Chrome
Published Jul 23, 2026
Updated Jul 24, 2026
Reserved Jul 23, 2026

CISA Vulnrichment

Updated Jul 24, 2026

NVD

Status Analyzed
Modified Jul 27, 2026

Red Hat

Severity Important
Public date Jul 23, 2026
Bugzilla 2506636

ENISA EUVD

Assigner Chrome
Published Jul 23, 2026
Updated Jul 24, 2026

GitHub

No data