Executive brief
A security vulnerability exists in the Google Chrome web browser's media processing components. By tricking a user into visiting a specially crafted website, a remote attacker could potentially execute malicious code on the user's computer. While the attack is limited by the browser's security sandbox, it could still lead to unauthorized access to data or further system compromise.
Technical details
A use-after-free (UAF) vulnerability exists in the Codecs component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during the processing of media content, allowing an attacker to reference memory after it has been freed. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious HTML page. Successful exploitation allows for arbitrary code execution within the context of the Chromium sandbox. The issue is resolved in Google Chrome version 147.0.7727.101 and later.
Affected products
- Google Chrome prior to 147.0.7727.101
Timeline
- 2026-03-25: disclosed: Reported by researcher Syn4pse
- 2026-04-15: advisory: Google released security advisory and fix details
- 2026-04-15: patched: Fixed in version 147.0.7727.101/102