
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-11668 is an Uninitialized Use in Codecs vulnerability in Google Chrome on Linux and ChromeOS that allows a remote attacker to leak cross-origin data via a crafted video file. It was reported internally by Google on 2026-05-21 and publicly disclosed on June 8–9, 2026, as part of a 74-fix stable channel update. Affected versions are Google Chrome prior to 149.0.7827.103 on Linux and ChromeOS. It carries a CVSS v3.1 base score of 4.3 (Medium), with Chromium internally rating it as High severity (Chrome Releases, GitHub Advisory).
The vulnerability is classified as CWE-457 (Use of Uninitialized Variable), occurring within Chrome's codec implementation on Linux and ChromeOS platforms. When Chrome processes a specially crafted video file, uninitialized memory in the codec subsystem may be read and its contents exposed to a remote attacker, enabling cross-origin data leakage. Exploitation requires user interaction — specifically, a victim must open or be directed to a malicious video file — but no special privileges are required on the attacker's side. The Chromium issue tracker entry is #515419790, though full bug details remain restricted pending broad user update (Chrome Releases, GitHub Advisory).
Successful exploitation results in a confidentiality breach: uninitialized memory contents from Chrome's codec processing can be leaked to a remote attacker, potentially exposing sensitive cross-origin data from other websites or browser tabs. There is no integrity or availability impact. The scope is limited to the affected browser process, with no evidence of lateral movement potential; however, leaked cross-origin data could include authentication tokens, page content, or other sensitive information from co-resident web origins (GitHub Advisory, Chrome Releases).
Google has released a patch in Chrome stable channel version 149.0.7827.102/.103 (Windows/Mac) and 149.0.7827.102 (Linux), which addresses CVE-2026-11668 along with 73 other security fixes. Users and administrators should update Google Chrome and ChromeOS to version 149.0.7827.103 or later immediately. As a temporary precaution prior to patching, users should avoid opening video files from untrusted or unknown sources. Enterprise administrators may consider restricting access to untrusted media content at the network level until systems are updated (Chrome Releases, GitHub Advisory).
The CIS issued an advisory noting that multiple vulnerabilities in Google Chrome, including CVE-2026-11668, could allow for arbitrary code execution or data leakage, recommending prompt patching. Tenable and Qualys both released detection plugins for this vulnerability shortly after disclosure. The broader Chrome update received attention primarily due to the co-disclosed zero-day CVE-2026-11645, with CVE-2026-11668 receiving comparatively less individual focus given its lower CVSS score and absence of active exploitation (CIS Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."