CVE-2026-10998: Google Chrome

Medium severity, CVSS 4.0. EPSS: 0.1% chance of exploitation in the next 30 days.

Out of bounds read in Media in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to perform an out of bounds memory read via malicious network traffic. (Chromium security severity: Medium)

Affected products

  • Google Chrome: before 149.0.7827.53 (fixed in 149.0.7827.53)

Published 2026-06-04. Last modified 2026-07-22.