Executive brief
A vulnerability in Google Chrome's audio processing component could allow a malicious website to access sensitive information from the browser's memory. This occurs when a user visits a specially crafted webpage, potentially exposing private data from other open tabs or browser processes. Users should update to the latest version of Chrome to mitigate this risk.
Technical details
A heap-based buffer overflow (CWE-122) exists in the WebAudio component of Google Chrome. The vulnerability is triggered when the browser processes a specially crafted HTML page containing malicious audio content. A remote, unauthenticated attacker can exploit this flaw to perform an out-of-bounds memory read, potentially allowing them to extract sensitive information from the browser's process memory. The attack requires user interaction (visiting a malicious site). The issue is resolved in Chrome version 147.0.7727.55.
Affected products
- Google Chrome prior to 147.0.7727.55
Timeline
- 2026-03-08: disclosed: Reported by Syn4pse
- 2026-04-07: patched: Stable channel update released
- 2026-04-08: advisory: CVE published