CVE-2026-13018

Summary

Insufficient validation of untrusted input in Codecs in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially perform out of bounds memory access via a crafted video file. (Chromium security severity: Low)

Affected Software

VendorProductVersion RangeStatus
GoogleChrome147.0.7727.55 < 147.0.7727.55affected

Weaknesses

  • CWE-20: Insufficient validation of untrusted input

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References