Executive brief
A vulnerability exists in Google Chrome's WebCodecs component, which is used by the browser to handle audio and video processing. A remote attacker could use a specially crafted website to trick the browser into leaking sensitive information from its memory. While this could potentially expose private data, the impact is considered low by the manufacturer.
Technical details
A side-channel information leakage vulnerability (CWE-1300) exists in the WebCodecs component of Google Chrome. The flaw allows a remote attacker to bypass memory isolation boundaries and extract sensitive information from the browser's process memory. Exploitation is achieved by enticing a user to visit a maliciously crafted HTML page that leverages WebCodecs to perform timing or other side-channel measurements. This vulnerability was addressed in Chrome version 151.0.7922.72.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in Stable Channel Update 151.0.7922.71/.72
- 2026-07-30: disclosed: NVD publication date