Executive brief
Google Chrome is a widely used web browser. A vulnerability in its WebML component could allow a malicious website to access sensitive information from the browser's memory. This could lead to the exposure of private data if a user visits a specially crafted webpage.
Technical details
A heap-based buffer overflow (CWE-122) exists in the WebML component of Google Chrome. The vulnerability is triggered when the browser processes a specially crafted HTML page. A remote, unauthenticated attacker can exploit this flaw to read sensitive information from the browser's process memory. This requires user interaction, specifically enticing a user to visit a malicious website. The issue was addressed in Chrome version 147.0.7727.55.
Affected products
- Google Chrome prior to 147.0.7727.55
Timeline
- 2026-03-14: other: Vulnerability reported to Chromium project
- 2026-04-07: patched: Chrome 147.0.7727.55 released to stable channel
- 2026-04-08: disclosed: CVE published