Executive brief
A security vulnerability exists in Google Chrome's WebCodecs component, which handles low-level audio and video processing. An attacker could exploit this by tricking a user into visiting a specially crafted website, potentially allowing the attacker to run unauthorized code on the user's computer. While the impact is limited by the browser's security sandbox, it still poses a significant risk to the integrity of the application and user data.
Technical details
A use-after-free (UAF) vulnerability exists in the WebCodecs component of Google Chrome prior to version 148.0.7778.216. The flaw is triggered when the browser incorrectly manages memory during the processing of media codecs, allowing a remote attacker to exploit the memory corruption via a malicious HTML page. If successfully exploited, an attacker can achieve arbitrary code execution (ACE) within the context of the browser's sandboxed process. This requires no special privileges other than convincing a user to navigate to a controlled URL. Users should update to version 148.0.7778.216 or later to mitigate this risk.
Affected products
- Google Chrome Prior to 148.0.7778.216
Timeline
- 2026-05-27: patched: Stable channel update released for Windows, Mac, and Linux.
- 2026-05-28: disclosed: CVE published to the NVD.