Description
Uninitialized Use in WebCodecs in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-05-06
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an uninitialized use in the WebCodecs API within Google Chrome that can lead to the exposure of sensitive data from the browser process's memory. This flaw falls under the CWE-457 classification, which describes the use of a variable before it has been initialized, permitting an attacker to read unintended memory contents. The impact is limited to leakage of potentially sensitive information rather than arbitrary code execution or denial of service.

Affected Systems

Google Chrome is affected, specifically all releases prior to version 148.0.7778.96. Users running an older Chrome browser are at risk if they access webpages that include WebCodecs components.

Risk and Exploitability

The CVE provides no EPSS score, and it is not listed in the CISA KEV catalog, indicating that there are currently no known widespread exploits. However, the attack can be launched remotely by a malicious or compromised web page, which suggests that a user’s interaction with such content is a prerequisite. Because the flaw permits the reading of memory, the CVSS score of 6.5 classifies the severity as Medium and the likelihood is considered low to moderate in the absence of publicly known exploits.

Generated by OpenCVE AI on May 7, 2026 at 00:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Chrome to 148.0.7778.96 or newer
  • Disable the WebCodecs API via Chrome flags or group policy
  • Use a web filtering solution to block pages that attempt to use WebCodecs

Generated by OpenCVE AI on May 7, 2026 at 00:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6250-1 chromium security update
History

Thu, 07 May 2026 01:15:00 +0000

Type Values Removed Values Added
Title Uninitialized Memory Use in Chrome WebCodecs Causes Information Leakage

Wed, 06 May 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows

Wed, 06 May 2026 22:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 06 May 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 06 May 2026 21:15:00 +0000

Type Values Removed Values Added
Title Uninitialized Memory Use in Chrome WebCodecs Causes Information Leakage

Wed, 06 May 2026 18:30:00 +0000

Type Values Removed Values Added
Description Uninitialized Use in WebCodecs in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-457
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-05-06T21:51:43.237Z

Reserved: 2026-05-05T22:59:26.919Z

Link: CVE-2026-7982

cve-icon Vulnrichment

Updated: 2026-05-06T19:08:33.744Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-06T19:16:49.067

Modified: 2026-05-06T23:22:09.540

Link: CVE-2026-7982

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-07T01:00:14Z

Weaknesses