Chrome · Media
CVE-2026-12450
Logic Error in Media
Overview
High
Severity
—
CVSS
No
Exploited ITW
Fixed
Fix Status
Files Changed
media/mojo/common/media_type_converters.cc
Patch
From 8ccfcaceaff181bbe485c48bc4449464caede755 Mon Sep 17 00:00:00 2001 From: Vikram Pasupathy <[email protected]> Date: Thu, 21 May 2026 12:20:17 -0700 Subject: [PATCH] media: Fix incorrect CHECK for input validation The CHECK_GE should actually be CHECK_LE. Please refer to the bug for more information. Bug: 514531776 Change-Id: I49448eba3d612948eb95568d87283cd5a0dc1d38 Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7860091 Reviewed-by: Dale Curtis <[email protected]> Commit-Queue: Vikram Pasupathy <[email protected]> Reviewed-by: Alex Gough <[email protected]> Cr-Commit-Position: refs/heads/main@{#1634455} --- diff --git a/media/mojo/common/media_type_converters.cc b/media/mojo/common/media_type_converters.cc index 0630476..d08dc88 100644 --- a/media/mojo/common/media_type_converters.cc +++ b/media/mojo/common/media_type_converters.cc @@ -225,7 +225,7 @@ // Safe to CHECK here since this is into Mojo not From mojo (and thus not // untrusted input). CHECK_GT(input.data_size(), 0u); - CHECK_GE(input.data_size(), input.data_->span().size()); + CHECK_LE(input.data_size(), input.data_->span().size()); auto buffer_start = input.data_->span().begin(); auto buffer_end = buffer_start + input.data_size(); buffer->data.assign(buffer_start, buffer_end);
Loading diff…
Original Bug Report
reported by [email protected]
Incorrect fix for CVE-2026-7905
Steps to reproduce the problem
While backporting the patch for CVE-2026-7905 into our product, I found an issue in the patch at https://chromium-review.googlesource.com/c/chromium/src/+/7695435:
- DCHECK_GT(input.data_size(), 0u);
- DCHECK_GE(input.data_size(), input.data_->span().size());
+ // Safe to CHECK here since this is into Mojo not From mojo (and thus not
+ // untrusted input).
+ CHECK_GT(input.data_size(), 0u);
+ CHECK_GE(input.data_size(), input.data_->span().size());
Problem Description
For CHECK_GE(input.data_size(), input.data_->span().size());
This line asserts at runtime that the size of input’s data (input.data_size()) is greater than or equal to the size of the memory span pointed to by input.data_. That should be a typo. The correct patch should be:
CHECK_LE(input.data_size(), input.data_->span().size());
Additional Comments
Zhixin Tu
Summary
Incorrect fix for CVE-2026-7905
Additional Data
Category: Security
Chrome Channel: Stable
Regression: N/A \
References
On This Page