Description
Integer overflow in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit heap corruption via a crafted video file. (Chromium security severity: Low)
Published: 2026-04-08
Score: n/a
EPSS: n/a
KEV: No
Impact: Potential heap corruption
Action: Update Chrome
AI Analysis

Impact

An integer overflow in the Media component of Google Chrome before 147.0.7727.55 can be triggered by a specially crafted video file. The overflow corrupts heap memory, and while the vulnerability is classified as low, it could potentially allow a remote attacker to execute arbitrary code if successfully exploited.

Affected Systems

Users running Google Chrome versions earlier than 147.0.7727.55 are affected. The flaw exists only in the media processing subsystem and does not apply to other parts of the browser.

Risk and Exploitability

The exploitation likelihood is not quantified in EPSS and the vulnerability is not listed in CISA’s KEV catalog. The low CVSS score indicates limited ease of exploitation. The attack vector is inferred to be remote delivery of a malicious video file that is then processed by the victim’s browser, requiring crafted input and possibly additional conditions to succeed.

Generated by OpenCVE AI on April 8, 2026 at 23:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 147.0.7727.55 or later.

Generated by OpenCVE AI on April 8, 2026 at 23:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 09 Apr 2026 08:30:00 +0000

Type Values Removed Values Added
Title Potential Heap Corruption from Integer Overflow in Chrome Media Processing
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 08 Apr 2026 21:30:00 +0000

Type Values Removed Values Added
Description Integer overflow in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit heap corruption via a crafted video file. (Chromium security severity: Low)
Weaknesses CWE-472
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-04-08T21:21:03.818Z

Reserved: 2026-04-08T19:34:44.856Z

Link: CVE-2026-5908

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-04-08T22:16:30.677

Modified: 2026-04-08T22:16:30.677

Link: CVE-2026-5908

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-09T08:26:10Z

Weaknesses