CVE-2026-10998

EUVD-2026-34447
Out of bounds read in Media in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to perform an out of bounds memory read via malicious network traffic. (Chromium security severity: Medium)
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4 MEDIUM
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 1%
Affected Products (NVD)
VendorProductVersion
googlechrome
𝑥
< 149.0.7827.53
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
chromium
bookworm
150.0.7871.100-1~deb12u1
fixed
bookworm (security)
150.0.7871.124-1~deb12u1
fixed
bullseye
vulnerable
bullseye (security)
vulnerable
forky
150.0.7871.124-1
fixed
sid
150.0.7871.124-1
fixed
trixie
150.0.7871.100-1~deb13u1
fixed
trixie (security)
150.0.7871.124-1~deb13u1
fixed