Description
Uninitialized Use in WebCodecs in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-04-08
Score: n/a
EPSS: n/a
KEV: No
Impact: Sensitive Data Exposure
Action: Apply Patch
AI Analysis

Impact

An uninitialized use bug in the WebCodecs API of Google Chrome allows a remote attacker to read potentially sensitive data from the browser's process memory when a specially crafted HTML page is loaded. The flaw is triggered when WebCodecs code references memory that has not been properly initialized, leading to leakage of information that might include credentials or other private data. Because this vulnerability is triggered by a web page, it can be exploited by any site that an attacker controls or by executing a malicious script in a victim's browser session.

Affected Systems

Google Chrome browsers running versions before 147.0.7727.55 are affected. The safety warning applies to the stable desktop channel used on Windows, macOS, and Linux. Users running older releases or manually installed build versions that have not applied the fix are at risk.

Risk and Exploitability

Chromium assigns medium severity to this issue. EPSS data is not available and the vulnerability is not listed in CISA’s KEV catalog, so publicly reported exploit activity is unknown. If an attacker can host a malicious web page, the bug can be triggered remotely without any additional authentication. The overall risk is moderate, driven primarily by the ease of attack via a standard web page and the potential value of the leaked memory contents. Timely patching is advisable to eliminate the exposure.

Generated by OpenCVE AI on April 8, 2026 at 22:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check if your Chrome version is older than 147.0.7727.55 by selecting Chrome > About Google Chrome.
  • Update Chrome to the latest stable release, which includes the WebCodecs fix.
  • Restart the browser after the update to ensure the new code is in use.

Generated by OpenCVE AI on April 8, 2026 at 22:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 09 Apr 2026 08:30:00 +0000

Type Values Removed Values Added
Title Uninitialized Use in WebCodecs Allows Sensitive Data Exposure
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 08 Apr 2026 21:30:00 +0000

Type Values Removed Values Added
Description Uninitialized Use in WebCodecs in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-457
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-04-08T21:20:52.176Z

Reserved: 2026-04-08T19:34:39.633Z

Link: CVE-2026-5888

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-04-08T22:16:28.667

Modified: 2026-04-08T22:16:28.667

Link: CVE-2026-5888

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-09T08:26:30Z

Weaknesses