Junglewise Threat Intelligence

CVE-2026-5907: Google Chrome out of bounds read in Media

CVE-2026-5907 · Severity: high · CVSS 8.1 · Published 2026-04-08

Technologies: Apple macOS, Microsoft Windows, Google Chrome, Linux Kernel. Vendors: Apple, Microsoft, Google, Linux.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its media processing component could allow a remote attacker to read sensitive information from the computer's memory if a user is tricked into opening a specially crafted video file. This could lead to the exposure of private data or help an attacker bypass security protections.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in the Media component of Google Chrome due to insufficient data validation. A remote, unauthenticated attacker can exploit this by enticing a user to open or view a maliciously crafted video file. Successful exploitation allows the attacker to perform an out-of-bounds memory read, which can lead to information disclosure or be used as a primitive in more complex exploit chains. The issue is resolved in Google Chrome version 147.0.7727.55.

Affected products

  • Google Chrome prior to 147.0.7727.55

Timeline

  • 2026-02-15: disclosed: Reported to Chromium by Luke Francis
  • 2026-04-07: patched: Fixed in Chrome 147 stable channel release
  • 2026-04-08: advisory: NVD publication date

References

Related threats