CVE-2026-10998

Out of bounds read in Media in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to perform an out of bounds memory read via malicious network traffic. (Chromium security severity: Medium)
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
OR cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

06 Jun 2026, 01:53

Type Values Removed Values Added
References () https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop.html - () https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop.html - Vendor Advisory
References () https://issues.chromium.org/issues/486536242 - () https://issues.chromium.org/issues/486536242 - Permissions Required
First Time Apple macos
Google
Linux
Apple
Linux linux Kernel
Google chrome
Microsoft windows
Microsoft
CPE cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

05 Jun 2026, 12:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.0

04 Jun 2026, 23:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-04 23:17

Updated : 2026-06-06 01:53


NVD link : CVE-2026-10998

Mitre link : CVE-2026-10998

CVE.ORG link : CVE-2026-10998


JSON object : View

Products Affected

google

  • chrome

microsoft

  • windows

apple

  • macos

linux

  • linux_kernel
CWE
CWE-125

Out-of-bounds Read