Executive brief
Google Chrome is a widely used web browser. A vulnerability in its media processing component could allow an attacker to compromise a user's computer if they are tricked into opening a specially crafted video file. This could lead to unauthorized access to data or the ability to run malicious code on the affected system.
Technical details
An integer overflow vulnerability exists in the Media component of Google Chrome. The flaw is triggered when the browser processes a specially crafted video file, leading to heap corruption. A remote, unauthenticated attacker can exploit this by inducing a user to visit a malicious website or open a malicious video file (User Interaction required). Successful exploitation could lead to arbitrary code execution or a denial-of-service condition. The vulnerability was addressed in Chrome version 147.0.7727.55.
Affected products
- Google Chrome prior to 147.0.7727.55
Timeline
- 2026-02-17: disclosed: Reported to Chromium by Ameen Basha M K & Mohammed Yasar B
- 2026-04-07: patched: Fixed in Chrome Stable Channel Update 147.0.7727.55
- 2026-04-08: advisory: NVD publication date