Skip to main content
Vulnerability Database/CVE-2026-106262

CVE-2026-106262: Google Chrome GetUserMedia RCE Vulnerability

CVE-2026-106262 is a remote code execution flaw in Google Chrome GetUserMedia that allows attackers to spoof UI elements after compromising the renderer process. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2026-106262 Overview

CVE-2026-106262 is an incomplete cleanup vulnerability [CWE-459] in the GetUserMedia component of Google Chrome versions prior to 155.0.8059.39. The flaw allows a remote attacker who has already compromised the renderer process to spoof user interface elements through a crafted HTML page. Successful exploitation requires both prior renderer compromise and user interaction via social engineering. Google classified the Chromium security severity as Medium.

Critical Impact

An attacker leveraging a compromised renderer can spoof UI elements tied to media capture, potentially tricking users into granting camera or microphone access they would otherwise deny.

Affected Products

  • Google Chrome versions prior to 155.0.8059.39 (Desktop)
  • Chromium-based browsers that incorporate the vulnerable GetUserMedia code path
  • Downstream distributions bundling pre-155 Chromium builds

Discovery Timeline

  • 2026-10-06 - CVE-2026-106262 published to the National Vulnerability Database
  • 2026-10-07 - Last updated in NVD database

Technical Details for CVE-2026-106262

Vulnerability Analysis

The vulnerability resides in Chrome's GetUserMedia implementation, the Web API that handles access to microphone and camera devices. Incomplete cleanup leaves residual UI state or object references after a media capture session ends or is interrupted. An attacker who has already achieved code execution inside the renderer process can abuse this residual state to render spoofed UI elements. The spoofed elements can misrepresent permission prompts, origin indicators, or active capture status to the user.

Exploitation is non-trivial. The attacker must chain this flaw with a prior renderer compromise and also convince the user to interact with the crafted content. These prerequisites explain why Google assigned a Medium severity rating despite the UI spoofing impact.

Root Cause

The root cause is incomplete cleanup [CWE-459] of resources associated with the GetUserMedia flow. When media capture sessions terminate abnormally or transition states, the component fails to fully reset UI-related objects. This leftover state becomes a primitive that a compromised renderer can repurpose to overlay or misrepresent trusted browser UI surfaces.

Attack Vector

The attack vector is network-based but requires high complexity and user interaction. An attacker first delivers a payload that compromises the renderer process, typically through a separate vulnerability or malicious extension. The attacker then serves a crafted HTML page that triggers the incomplete cleanup condition in GetUserMedia. The resulting spoofed UI elements can mislead the user into approving media capture or trusting attacker-controlled content as if it originated from a legitimate site. Technical specifics are tracked in Chromium Issue Tracker #533066295.

Detection Methods for CVE-2026-106262

Indicators of Compromise

  • Chrome browser processes running versions earlier than 155.0.8059.39 after the patch release window
  • Unexpected getUserMedia() API invocations originating from untrusted or newly loaded origins
  • Anomalous renderer process crashes or restarts preceding media permission prompts
  • User reports of misleading or duplicated permission dialogs for camera or microphone access

Detection Strategies

  • Inventory installed Chrome versions across managed endpoints and flag any build earlier than 155.0.8059.39
  • Monitor browser telemetry for abnormal rates of media capture permission requests from untrusted domains
  • Correlate renderer process anomalies with subsequent WebRTC or GetUserMedia activity in endpoint logs

Monitoring Recommendations

  • Enable Chrome enterprise reporting to centralize browser version and extension telemetry
  • Collect endpoint process events for chrome.exe child renderers and alert on repeated unexpected terminations
  • Track outbound WebRTC signaling patterns that could indicate unauthorized media capture following UI spoofing

How to Mitigate CVE-2026-106262

Immediate Actions Required

  • Update Google Chrome to version 155.0.8059.39 or later across all managed desktops
  • Verify Chromium-based browsers (Edge, Brave, Opera, Vivaldi) have incorporated the upstream fix before deeming them patched
  • Review and remove unverified browser extensions that could contribute to renderer compromise
  • Reinforce user awareness training covering permission prompts for camera and microphone access

Patch Information

Google released the fix in the Chrome Stable channel update that shipped version 155.0.8059.39. Refer to the Google Chrome Stable Update advisory for the full list of fixes included in this release. Managed environments should push the update through enterprise deployment tooling and confirm restart compliance.

Workarounds

  • Restrict GetUserMedia access via Chrome enterprise policies such as VideoCaptureAllowedUrls and AudioCaptureAllowedUrls until patching completes
  • Disable camera and microphone access by default using DefaultAudioCaptureSetting and DefaultVideoCaptureSetting policies
  • Enforce site isolation and sandboxing policies to reduce the blast radius of any renderer compromise
bash
# Configuration example: Chrome enterprise policy to block default media capture
# Windows Registry (HKLM\Software\Policies\Google\Chrome)
DefaultAudioCaptureSetting = 2   # Block by default
DefaultVideoCaptureSetting = 2   # Block by default

# macOS plist (com.google.Chrome)
defaults write com.google.Chrome DefaultAudioCaptureSetting -int 2
defaults write com.google.Chrome DefaultVideoCaptureSetting -int 2

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.