Executive brief
Google Chrome is a widely used web browser. A vulnerability in its media handling component could allow a remote attacker to execute unauthorized code on a user's system if the attacker has already compromised the browser's rendering process. This could lead to the theft of sensitive information or further compromise of the device, though the attack is partially contained within the browser's security sandbox.
Technical details
An improper input validation vulnerability (CWE-20) exists in the Media component of Google Chrome. The flaw allows a remote attacker to achieve arbitrary code execution within the browser's sandbox. To exploit this, an attacker must first compromise the renderer process and then entice a user to visit a specially crafted HTML page. The vulnerability was addressed in version 147.0.7727.55. While Chromium developers rated this as Medium severity, CISA-ADP has assigned a CVSS score of 8.8 (High).
Affected products
- Google Chrome prior to 147.0.7727.55
Timeline
- 2026-02-15: other: Reported by researcher xmzyshypnc
- 2026-04-07: patched: Fixed in Chrome 147.0.7727.55 stable channel update
- 2026-04-08: disclosed: Initial NVD publication