Junglewise Threat Intelligence

CVE-2026-5910: Google Chrome integer overflow in Media

CVE-2026-5910 · Severity: high · CVSS 8.8 · Published 2026-04-08

Technologies: Apple macOS, Microsoft Windows, Google Chrome, Linux Kernel. Vendors: Apple, Microsoft, Google, Linux.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its media processing component could allow an attacker to compromise a user's computer if they are tricked into opening a specially crafted video file. This could lead to unauthorized access to data or the ability to run malicious code on the affected system.

Technical details

An integer overflow vulnerability exists in the Media component of Google Chrome. The flaw is triggered when the browser processes a specially crafted video file, leading to heap corruption. A remote, unauthenticated attacker can exploit this by inducing a user to visit a malicious website or open a malicious video file (User Interaction required). Successful exploitation could lead to arbitrary code execution or a denial-of-service condition. The vulnerability was addressed in Chrome version 147.0.7727.55.

Affected products

  • Google Chrome prior to 147.0.7727.55

Timeline

  • 2026-02-17: disclosed: Reported to Chromium by Ameen Basha M K & Mohammed Yasar B
  • 2026-04-07: patched: Fixed in Chrome Stable Channel Update 147.0.7727.55
  • 2026-04-08: advisory: NVD publication date

References

Related threats