Executive brief
Google Chrome is a widely used web browser. A vulnerability in its media processing component could allow a remote attacker to read sensitive information from the computer's memory if a user is tricked into opening a specially crafted video file. This could lead to the exposure of private data or help an attacker bypass security protections.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in the Media component of Google Chrome due to insufficient data validation. A remote, unauthenticated attacker can exploit this by enticing a user to open or view a maliciously crafted video file. Successful exploitation allows the attacker to perform an out-of-bounds memory read, which can lead to information disclosure or be used as a primitive in more complex exploit chains. The issue is resolved in Google Chrome version 147.0.7727.55.
Affected products
- Google Chrome prior to 147.0.7727.55
Timeline
- 2026-02-15: disclosed: Reported to Chromium by Luke Francis
- 2026-04-07: patched: Fixed in Chrome 147 stable channel release
- 2026-04-08: advisory: NVD publication date