CVE-2026-13858

NameCVE-2026-13858
DescriptionOut of bounds read in FFmpeg in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted video file. (Chromium security severity: Medium)
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-4672-1, DSA-6361-1, DSA-6378-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
chromium (PTS)bookworm150.0.7871.100-1~deb12u1fixed
bookworm (security)153.0.8010.52-1~deb12u1fixed
trixie150.0.7871.181-1~deb13u1fixed
trixie (security)153.0.8010.52-1~deb13u1fixed
forky150.0.7871.181-1fixed
sid153.0.8010.52-1fixed
ffmpeg (PTS)bookworm, bookworm (security)7:5.1.9-0+deb12u1vulnerable
trixie (security), trixie7:7.1.5-0+deb13u1fixed
forky7:8.1.2-2vulnerable
sid7:9.0.2-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
chromiumsourcebullseye(unfixed)end-of-life
chromiumsourcebookworm150.0.7871.46-1~deb12u1DLA-4672-1
chromiumsourcetrixie150.0.7871.46-1~deb13u1DSA-6378-1
chromiumsource(unstable)150.0.7871.46-1
ffmpegsourcetrixie7:7.1.5-0+deb13u1DSA-6361-1
ffmpegsource(unstable)(unfixed)

Notes

[bullseye] - chromium <end-of-life> (see #1061268)
[trixie] - ffmpeg <postponed> (Wait until fixed in 7.1.x upstream branch)
https://issues.chromium.org/issues/507090179
https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/22976
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/256d93413f260e1524c2ab994dc72c4edaa0d04c (n9.0)
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/cb8a5ca8ab36884064ac4de5175ae82c93edfcb2 (n7.1.5)

Search for package or bug name: Reporting problems