Description
Side-channel information leakage in Media in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-05-06
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A side‑channel flaw was found in the media handling component of Google Chrome that permits a remote attacker to leak data from a different origin. By loading a specially crafted HTML page, an attacker can extract content that should otherwise be protected by the same‑origin policy. The CWE classification is 1300, indicating information disclosure through subtle side‑channel effects. The Chromium project rates the overall severity as low because the attack requires no privileged access and is limited to information leakage rather than code execution or denial of service.

Affected Systems

Google Chrome browsers running any version earlier than 148.0.7778.96 are affected. The flaw does not exist in the 148.0.7778.96 release or later releases.

Risk and Exploitability

The danger level is moderate: while the issue leads only to data leakage, it can be exploited from any web page the user loads, making it viable for attackers who can host malicious content. With the EPSS score unavailable and the vulnerability absent from CISA’s Known Exploited Vulnerabilities catalog, the likelihood of mass exploitation is low, but targeted attacks remain plausible. The CVSS score for this vulnerability is 3.1.

Generated by OpenCVE AI on May 7, 2026 at 00:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 148.0.7778.96 or newer, the fix for this media side‑channel flaw.
  • If immediate updating is not feasible, restrict media loading from untrusted origins by applying a content security policy that blocks cross‑origin media requests, thereby limiting the window of exploitation.
  • Block media requests to external origins using network firewall or proxy rules to prevent exploitation when an update cannot be applied immediately.

Generated by OpenCVE AI on May 7, 2026 at 00:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6250-1 chromium security update
History

Thu, 07 May 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows

Thu, 07 May 2026 01:15:00 +0000

Type Values Removed Values Added
Title Side‑Channel Information Leakage in Chrome Media Handling

Wed, 06 May 2026 22:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 06 May 2026 21:45:00 +0000

Type Values Removed Values Added
Title Side‑Channel Information Leakage in Chrome Media Handling

Wed, 06 May 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 06 May 2026 18:30:00 +0000

Type Values Removed Values Added
Description Side-channel information leakage in Media in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-1300
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-05-06T21:45:55.078Z

Reserved: 2026-05-05T22:59:36.057Z

Link: CVE-2026-8017

cve-icon Vulnrichment

Updated: 2026-05-06T20:55:56.945Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-06T19:16:52.663

Modified: 2026-05-07T15:29:05.613

Link: CVE-2026-8017

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-07T01:00:14Z

Weaknesses