Source status: Chrome's stable-channel release explicitly says the issue was reported by Wongi Lee of Theori with Xint Code and Jungwoo Lee and rates it Medium.
Summary
CVE-2026-13858 is an out-of-bounds read in Chrome’s FFmpeg-related code. Chrome assigned a $3,000 reward and published the fix with Chrome 150.
Attribution
This is direct vendor attribution and is separate from Xint’s public tracker: Chrome itself names Xint Code in the reporter line.
References
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.