Description
Race in WebCodecs in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-04-08
Score: n/a
EPSS: n/a
KEV: No
Impact: Sensitive information disclosure
Action: Immediate patch
AI Analysis

Impact

A race condition in the WebCodecs component of Google Chrome could allow a remote attacker to read fragments of process memory after a crafted HTML page is loaded. This flaw may expose sensitive information if the memory contains credentials, cryptographic keys, or other confidential data. The weakness corresponds to CWE‑362, which is a modification order or synchronization error. The vulnerability is listed as medium severity, indicating that while likely insufficient alone for full data exfiltration, it can facilitate other attacks or lead to partial information leaks.

Affected Systems

Google Chrome browsers running any version prior to 147.0.7727.55 are vulnerable. The issue was identified in the Chrome stable channel and applies to the desktop build of the browser. Users with older releases should upgrade to the patched version.

Risk and Exploitability

The exploit requires the attacker to host a malicious web page that the victim visits. The attack can be carried out in a normal browsing session without special permissions. Because the flaw is a synchronization race, injection of crafted script or media data is sufficient. No exploit probability score is published and the vulnerability is not listed in the CISA KEV catalog, suggesting it is not actively weaponized. Nevertheless, the medium severity and the ability to obtain memory contents warrant prompt remediation. The primary risk is leakage of confidential data from the browser process.

Generated by OpenCVE AI on April 8, 2026 at 22:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 147.0.7727.55 or later and enable automatic updates to ensure timely patch delivery.
  • Avoid loading untrusted or suspicious web pages until the browser is updated.
  • Monitor for any new advisories regarding this issue in the Chrome release blog or Chromium issue tracker.

Generated by OpenCVE AI on April 8, 2026 at 22:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 09 Apr 2026 08:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 08 Apr 2026 21:30:00 +0000

Type Values Removed Values Added
Description Race in WebCodecs in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-362
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-04-08T21:20:53.327Z

Reserved: 2026-04-08T19:34:40.168Z

Link: CVE-2026-5890

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-04-08T22:16:28.873

Modified: 2026-04-08T22:16:28.873

Link: CVE-2026-5890

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-09T08:26:28Z

Weaknesses