Executive brief
Google Chrome is a widely used web browser for accessing the internet. A vulnerability in its media handling component could allow a malicious website to execute unauthorized code on a user's computer. While the browser's security sandbox limits the immediate reach of such an attack, it could still lead to data theft or serve as a stepping stone for a full system compromise.
Technical details
A use-after-free (UAF) vulnerability exists in the Media component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory lifecycle during the processing of media content. A remote, unauthenticated attacker can exploit this by enticing a user to visit a maliciously crafted HTML page. Successful exploitation allows for arbitrary code execution (ACE) within the context of the Chromium sandbox. The vulnerability was addressed in version 147.0.7727.55.
Affected products
- Google Chrome prior to 147.0.7727.55
Timeline
- 2026-03-13: disclosed: Reported to Chromium by researcher c6eed09fc8b174b0f3eebedcceb1e792
- 2026-04-07: patched: Stable channel update released for Windows, Mac, and Linux
- 2026-04-08: advisory: NVD publication date