CVE-2026-12033: Medium severity Google Google Chrome vulnerability
Out of bounds read in VideoCapture in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the GPU process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 149.0.7827.114 - Upgrade
Upgrade
Google Chrometo a version that resolves this vulnerability.Fixed in 149.0.7827.115
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2026-12033?
The severity of CVE-2026-12033 is rated medium with a score of 5.3 according to the CVSS 3.1 metrics.
How do I fix CVE-2026-12033?
To fix CVE-2026-12033, update Google Chrome to version 149.0.7827.115 or later.
What type of vulnerability is CVE-2026-12033?
CVE-2026-12033 is an out-of-bounds read vulnerability in the VideoCapture component of Google Chrome.
What can be potentially compromised due to CVE-2026-12033?
CVE-2026-12033 may allow a remote attacker to access potentially sensitive information from process memory.
In which versions of Google Chrome is CVE-2026-12033 present?
CVE-2026-12033 is present in Google Chrome versions prior to 149.0.7827.115.