← Back to search

CVE-2026-13018

4.3 MEDIUM

Published 2026-09-28 · Updated 2026-09-29

AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.

NVD description

Insufficient validation of untrusted input in Codecs in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially perform out of bounds memory access via a crafted video file. (Chromium security severity: Low)

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

Weaknesses

CWE-20

Vendors

google

Products

chrome

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.