CVE-2026-13018

MEDIUMCVSS 4.30% EPSS

Insufficient validation of untrusted input in Codecs in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially perform out of bounds memory access via a crafted video file. (Chromium security severity: Low)

Published 2026-09-28 · last modified 2026-09-29

Affected products

VendorProduct
googlechrome

Full record at NVD ↗

← Get alerted the moment a CVE hits your gear — subscribe free

Ncerio by BeyondNets · data from NVD, CISA KEV, EPSS.