CVE-2026-12450: Inappropriate implementation in Google Chrome
A vulnerability in Google Chrome prior to version 149.0.7827.155 in the Media component allows a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. The issue is classified with a medium severity and has a CVSS score of 6.5. No official patch or remediation level is explicitly stated in the provided data, and no known exploits are reported in the wild.
AI Analysis
Technical Summary
CVE-2026-12450 is a vulnerability in the Media implementation of Google Chrome before version 149.0.7827.155. It allows a remote attacker to extract potentially sensitive information from process memory by delivering a specially crafted HTML page. The vulnerability is recognized by Chromium with a high security severity classification, though the CVSS score rates it as medium severity. The vulnerability does not require privileges and can be triggered with user interaction. No official fix or remediation details are provided in the input, but a vendor advisory URL is available for further information.
Potential Impact
An attacker can remotely obtain sensitive information from the memory of the Chrome process by convincing a user to visit a maliciously crafted HTML page. This could lead to information disclosure without requiring prior privileges. There is no indication of integrity or availability impact. No known exploits in the wild have been reported.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory at https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_01750511403.html for current remediation guidance. Until an official fix is confirmed, users should exercise caution when visiting untrusted websites and consider updating Chrome to the latest available version once updates are released.
CVE-2026-12450: Inappropriate implementation in Google Chrome
Description
A vulnerability in Google Chrome prior to version 149.0.7827.155 in the Media component allows a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. The issue is classified with a medium severity and has a CVSS score of 6.5. No official patch or remediation level is explicitly stated in the provided data, and no known exploits are reported in the wild.
CVSS v3.1
Score 6.5medium
Affected software
pkg:github/chromium/chromiumRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-12450 is a vulnerability in the Media implementation of Google Chrome before version 149.0.7827.155. It allows a remote attacker to extract potentially sensitive information from process memory by delivering a specially crafted HTML page. The vulnerability is recognized by Chromium with a high security severity classification, though the CVSS score rates it as medium severity. The vulnerability does not require privileges and can be triggered with user interaction. No official fix or remediation details are provided in the input, but a vendor advisory URL is available for further information.
Potential Impact
An attacker can remotely obtain sensitive information from the memory of the Chrome process by convincing a user to visit a maliciously crafted HTML page. This could lead to information disclosure without requiring prior privileges. There is no indication of integrity or availability impact. No known exploits in the wild have been reported.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory at https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_01750511403.html for current remediation guidance. Until an official fix is confirmed, users should exercise caution when visiting untrusted websites and consider updating Chrome to the latest available version once updates are released.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Chrome
- Date Reserved
- 2026-06-16T19:38:27.903Z
- Cvss Version
- null
- State
- PUBLISHED
- Remediation Level
- null
- Vendor Advisory Urls
- [{"url":"https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_01750511403.html","vendor":"Google"}]
Threat ID: 6a31ffc60b89be68889b0197
Added to database: 06/17/2026, 02:00:38 UTC
Last enriched: 06/24/2026, 16:36:57 UTC
Last updated: 08/01/2026, 07:17:58 UTC
Views: 90
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.