All findings

CVE-2026-13858 medium

Chrome credits Theori with Xint Code on FFmpeg out-of-bounds read

Chrome 150 directly credits Wongi Lee of Theori with Xint Code, alongside Jungwoo Lee, for a Medium-severity FFmpeg out-of-bounds read.

Bug class
Out-of-bounds read
Affected codebase
Chromium FFmpeg integration
Credited system
Xint Code
Disclosed
June 30, 2026
Attribution
Direct source attribution
Severity
medium
Source status: Chrome's stable-channel release explicitly says the issue was reported by Wongi Lee of Theori with Xint Code and Jungwoo Lee and rates it Medium.

Summary

CVE-2026-13858 is an out-of-bounds read in Chrome’s FFmpeg-related code. Chrome assigned a $3,000 reward and published the fix with Chrome 150.

Attribution

This is direct vendor attribution and is separate from Xint’s public tracker: Chrome itself names Xint Code in the reporter line.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.