Executive brief
Google Chrome is a widely used web browser. A security vulnerability in the way the browser handles media codecs could allow an attacker to execute malicious code on a user's computer if they visit a specially crafted website. While the attack is limited by the browser's security sandbox, it could still lead to unauthorized actions or further compromise of the system.
Technical details
A use-after-free (UAF) vulnerability exists in the Codecs component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during the processing of media content, allowing a remote attacker to exploit the memory corruption via a specially crafted HTML page. Successful exploitation allows for arbitrary code execution (ACE) within the context of the Chromium sandbox. The vulnerability is reachable over the network and requires minimal user interaction (visiting a malicious site). Google has addressed this issue in version 147.0.7727.101.
Affected products
- Google Chrome prior to 147.0.7727.101
Timeline
- 2026-03-25: other: Reported to Google
- 2026-04-15: advisory: Vendor advisory published
- 2026-04-15: patched: Fixed in version 147.0.7727.101