Executive brief
A security vulnerability exists in Google Chrome's video processing components. By tricking a user into opening a specially crafted video file, a remote attacker could potentially access sensitive information stored in the browser's memory. This could lead to unauthorized data exposure or browser instability.
Technical details
A use-after-free (UAF) vulnerability exists in the Codecs component of Google Chrome. The flaw is triggered when the browser processes a specially crafted video file, leading to out-of-bounds memory access. An attacker can exploit this by hosting a malicious video file on a website and enticing a user to visit it. Successful exploitation could allow for information disclosure or potentially arbitrary code execution within the browser's sandbox. The issue is resolved in Google Chrome version 147.0.7727.101 and later.
Affected products
- Google Chrome prior to 147.0.7727.101
Timeline
- 2026-04-07: other: Reported by researcher c6eed09fc8b174b0f3eebedcceb1e792
- 2026-04-15: disclosed: Vulnerability published in Chrome Stable Channel Update
- 2026-04-15: patched: Fixed in version 147.0.7727.101