Overview
What is CVE-2026-10966?
Inappropriate implementation in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: High)
Vulnerability intelligence
CVE-2026-10966 and is rated Critical severity with a CVSS score of 9.6. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
Inappropriate implementation in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: High)