Junglewise Threat Intelligence

CVE-2026-13018: Google Chrome out-of-bounds memory access in Codecs

CVE-2026-13018 · Severity: info · Published 2026-09-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome contains a vulnerability in its video codec handling that could allow an attacker to access memory outside intended boundaries through a specially crafted video file. An attacker could exploit this to crash the browser or potentially execute code with the privileges of the Chrome process. This affects Chrome versions prior to 147.0.7727.55.

Technical details

The vulnerability stems from insufficient validation of untrusted input in the Codecs component of Chromium, allowing out-of-bounds memory access when processing crafted video files. Attack vector is network-based (remote delivery of malicious video file) with no authentication or special privileges required. An attacker gains the ability to read or write memory outside intended bounds, with potential for information disclosure or code execution depending on memory layout and heap state.

Affected products

  • Google Chrome prior to 147.0.7727.55

Timeline

  • 2026-09-28: disclosed
  • 2026-04: patched: Fixed in Chrome 147.0.7727.55

References

Related threats