Executive brief
Google Chrome is a widely used web browser. A vulnerability in its rendering engine, Blink, could allow a remote attacker to read sensitive information from the computer's memory if a user visits a specially crafted website. This could lead to the exposure of private data or help an attacker bypass other security protections.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in the Blink rendering engine of Google Chrome prior to version 147.0.7727.55. The flaw is triggered when the browser processes a specially crafted HTML page, allowing a remote attacker to read memory outside of the intended buffer. While Chromium developers classified the internal severity as Low, CISA-ADP has assigned a CVSS score of 8.1 (High), noting that the vulnerability can lead to significant information disclosure. The issue is resolved in Chrome version 147.0.7727.55 and later.
Affected products
- Google Chrome prior to 147.0.7727.55
Timeline
- 2026-02-24: disclosed: Reported by Vitaly Simonovich
- 2026-04-07: patched: Fixed in Chrome 147.0.7727.55 stable channel update
- 2026-04-08: advisory: NVD publication date