{"id":"CVE-2026-13018","published":"2026-09-28T19:16:49.033","lastModified":"2026-09-29T13:23:33.840","description":"Insufficient validation of untrusted input in Codecs in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially perform out of bounds memory access via a crafted video file. (Chromium security severity: Low)","cvssScore":4.3,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","cwes":["CWE-20"],"vendors":["google"],"products":["chrome"],"references":[{"url":"https://chromereleases.googleblog.com/2026/04/stable-channel-update-for-desktop.html","tags":["Release Notes","Vendor Advisory"]},{"url":"https://issues.chromium.org/issues/487950074","tags":["Permissions Required"]}],"exploitRefs":[],"hasPoc":false,"ai":null}