PT-2026-31525 · Google · Google Chrome
Luke Francis
·
Published
2026-02-15
·
Updated
2026-04-12
·
CVE-2026-5907
CVSS v2.0
9.4
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Google Chrome versions prior to 147.0.7727.55
Description
Insufficient data validation in the Media component of Google Chrome could allow a remote attacker to perform an out-of-bounds memory read using a crafted video file. Exploitation may lead to a denial-of-service.
Recommendations
Update Google Chrome to version 147.0.7727.55 or later.
Fix
RCE
Insufficient Verification of Data Authenticity
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Google Chrome