Description
Out of bounds read in WebCodecs in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform an out of bounds memory read via a crafted video file. (Chromium security severity: Medium)
Published: 2026-05-06
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A buffer overread occurs in the WebCodecs component of Google Chrome, allowing a remote attacker to read arbitrary memory data when a specially crafted video file is processed. The flaw is a classic out‑of‑bounds read (CWE‑125) and can expose sensitive information contained in the victim’s process address space. No privileged escalation or code execution is achievable solely through this vulnerability, but the data exposed may enable additional attacks or compromise user privacy.

Affected Systems

Google Chrome versions earlier than 148.0.7778.96 are affected. The vulnerability exists in the WebCodecs implementation shipped with those releases. Systems running the specified or older versions should be considered at risk until an update is applied.

Risk and Exploitability

The EPSS score is unavailable, and the vulnerability is not listed in the CISA KEV catalog, indicating a moderate exploitation risk. A remote attacker can trigger the overread by hosting a malicious video file or sending it to a victim via a vulnerable web page. The exploit requires no special conditions beyond the ability to deliver the crafted file to a Chrome instance running the affected version. The CVSS score of 4.3 reflects a Medium severity, suggesting that the risk is not trivial but warrants timely patching to prevent data leakage.

Generated by OpenCVE AI on May 7, 2026 at 01:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Chrome update (148.0.7778.96 or newer).
  • Disable or restrict WebCodecs usage through group policy or browser extensions if upgrading is delayed.
  • Monitor Google security notices for updates to WebCodecs to apply patches as soon as available.

Generated by OpenCVE AI on May 7, 2026 at 01:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6250-1 chromium security update
History

Thu, 07 May 2026 01:30:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Memory Read in Chrome WebCodecs via Crafted Video File

Wed, 06 May 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows

Wed, 06 May 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 06 May 2026 22:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 06 May 2026 20:45:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Memory Read in Chrome WebCodecs via Crafted Video File

Wed, 06 May 2026 18:30:00 +0000

Type Values Removed Values Added
Description Out of bounds read in WebCodecs in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform an out of bounds memory read via a crafted video file. (Chromium security severity: Medium)
Weaknesses CWE-125
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-05-06T21:59:20.276Z

Reserved: 2026-05-05T22:59:13.409Z

Link: CVE-2026-7933

cve-icon Vulnrichment

Updated: 2026-05-06T19:51:14.224Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-06T19:16:41.637

Modified: 2026-05-06T23:34:54.613

Link: CVE-2026-7933

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-07T01:15:17Z

Weaknesses