Description
Insufficient data validation in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform an out of bounds memory read via a crafted video file. (Chromium security severity: Low)
Published: 2026-04-08
Score: n/a
EPSS: n/a
KEV: No
Impact: Data Disclosure
Action: Patch Immediately
AI Analysis

Impact

Google Chrome contained a flaw in its media handling code where insufficient input validation allowed an attacker to craft a malicious video file that triggers an out‑of‑bounds memory read. The read occurs while processing the video, potentially exposing arbitrary data residing in Chrome’s process memory. The defect is characterized as a low‑severity vulnerability, implying that exploitation is not straightforward but still may reveal sensitive information to the attacker.

Affected Systems

Versions of Google Chrome earlier than 147.0.7727.55 on any supported platform are affected. The vulnerability is present in the Chrome browser’s media component that decodes video files. The flaw applies to the stable channel until the referenced update is installed.

Risk and Exploitability

The CVSS severity is low and the exploitation probability is unknown due to the lack of EPSS data. The vulnerability is not listed in the CISA KEV catalog, suggesting no known active exploits. A likely attack path involves a remote attacker delivering a crafted video file to a user’s browser, either via a malicious website or a tricked download. The read can be performed without additional privileges, providing potential for information disclosure. Given the limited impact level and no public exploit, the threat is moderate but should still be remediated promptly.

Generated by OpenCVE AI on April 8, 2026 at 22:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 147.0.7727.55 or newer to eliminate the flaw

Generated by OpenCVE AI on April 8, 2026 at 22:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 09 Apr 2026 08:30:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Memory Read in Chrome Media Processing
First Time appeared Google
Google chrome
Weaknesses CWE-125
Vendors & Products Google
Google chrome

Wed, 08 Apr 2026 21:30:00 +0000

Type Values Removed Values Added
Description Insufficient data validation in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform an out of bounds memory read via a crafted video file. (Chromium security severity: Low)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-04-08T21:21:03.423Z

Reserved: 2026-04-08T19:34:44.654Z

Link: CVE-2026-5907

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-04-08T22:16:30.580

Modified: 2026-04-08T22:16:30.580

Link: CVE-2026-5907

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-09T08:26:11Z

Weaknesses