Executive brief
A security vulnerability exists in Google Chrome's video processing component. An attacker could exploit this by tricking a user into visiting a specially crafted website, potentially allowing the attacker to run unauthorized code on the user's computer. While the attack is limited by Chrome's security sandbox, it still poses a significant risk to data privacy and system integrity.
Technical details
A use-after-free vulnerability exists in the Video component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during the processing of video content. A remote, unauthenticated attacker can exploit this by inducing a user to load a maliciously crafted HTML page. Successful exploitation allows for arbitrary code execution within the context of the Chrome renderer sandbox. This issue was resolved in version 147.0.7727.101 for Linux and 147.0.7727.101/102 for Windows and Mac.
Affected products
- Google Chrome prior to 147.0.7727.101
Timeline
- 2026-03-24: disclosed: Reported by Syn4pse
- 2026-04-15: patched: Fixed in version 147.0.7727.101/102
- 2026-04-15: advisory