Description
Integer overflow in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit heap corruption via a crafted video file. (Chromium security severity: Low)
Published: 2026-04-08
Score: n/a
EPSS: n/a
KEV: No
Impact: Potential Remote Code Execution via Heap Corruption
Action: Patch
AI Analysis

Impact

Chrome handles media streams by allocating buffers on the heap. The integer overflow occurs during the parsing of certain parameters in a video file, which can corrupt those buffers. If an attacker can successfully cause overflow, the corrupted heap may lead to arbitrary code execution or denial of service. The weakness is identified as CWE‑472: Integer Overflow or Wraparound.

Affected Systems

Google Chrome versions prior to 147.0.7727.55 on all platforms that support media playback are affected. The vulnerability applies to the stable channel of Chrome; no specific version rollbacks or isolated components were listed.

Risk and Exploitability

The CVSS score is not publicly disclosed, and there is no EPSS value available, making it difficult to quantify the likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a remote attacker delivering a specially crafted video file to a victim’s browser, possibly via a malicious website or email attachment. Because the flaw requires a crafted media payload, exploitation may require user interaction or favorable conditions, but the potential for remote code execution warrants immediate attention.

Generated by OpenCVE AI on April 8, 2026 at 22:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to version 147.0.7727.55 or later

Generated by OpenCVE AI on April 8, 2026 at 22:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 09 Apr 2026 08:30:00 +0000

Type Values Removed Values Added
Title Integer Overflow in Media Handling Leading to Potential Heap Corruption in Chrome
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 08 Apr 2026 21:30:00 +0000

Type Values Removed Values Added
Description Integer overflow in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit heap corruption via a crafted video file. (Chromium security severity: Low)
Weaknesses CWE-472
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-04-08T21:21:04.841Z

Reserved: 2026-04-08T19:34:45.984Z

Link: CVE-2026-5910

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-04-08T22:16:30.900

Modified: 2026-04-08T22:16:30.900

Link: CVE-2026-5910

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-09T08:26:08Z

Weaknesses