Executive brief
A vulnerability in Google Chrome's media processing component could allow a remote attacker to compromise a user's system. By tricking a user into opening a specially crafted video file or visiting a malicious website, an attacker could cause the browser to crash or potentially execute unauthorized code. This could lead to the theft of sensitive data or a complete takeover of the browser session.
Technical details
An integer overflow vulnerability exists in the Media component of Google Chrome. The flaw is triggered when the browser processes a specially crafted video file, leading to heap corruption. A remote, unauthenticated attacker can exploit this by hosting a malicious video file and inducing a user to view it. Successful exploitation could result in arbitrary code execution within the context of the browser's sandbox or a denial-of-service (browser crash). The issue was addressed in Chrome version 147.0.7727.55.
Affected products
- Google Chrome prior to 147.0.7727.55
Timeline
- 2026-02-17: disclosed: Reported to Chromium by Mohammed Yasar B & Ameen Basha M K
- 2026-04-07: patched: Fixed in Chrome stable channel update 147.0.7727.55
- 2026-04-08: advisory: NVD publication date