Junglewise Threat Intelligence

CVE-2026-5908: Google Chrome integer overflow in Media

CVE-2026-5908 · Severity: high · CVSS 8.8 · Published 2026-04-08

Technologies: Apple macOS, Microsoft Windows, Google Chrome, Linux Kernel. Vendors: Apple, Microsoft, Google, Linux.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its media processing component could allow a remote attacker to compromise a user's system if the user views a specially crafted video file. This could lead to unauthorized access to data or the ability for an attacker to run malicious code on the affected device.

Technical details

An integer overflow vulnerability exists in the Media component of Google Chrome. The flaw is triggered when the browser processes a specially crafted video file, leading to heap corruption. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious website or open a malicious video file (requiring user interaction). Successful exploitation could allow for arbitrary code execution or a denial-of-service condition within the browser's process. The issue is addressed in Chrome version 147.0.7727.55.

Affected products

  • Google Chrome prior to 147.0.7727.55

Timeline

  • 2026-02-17: disclosed: Reported to Chromium by Ameen Basha M K & Mohammed Yasar B
  • 2026-04-07: patched: Chrome 147 promoted to stable channel
  • 2026-04-08: advisory: NVD publication date

References

Related threats