Integer Overflow Vulnerability in Google Chrome Web Browser
CVE-2026-5274

8.8HIGH

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
1 April 2026

What is CVE-2026-5274?

An integer overflow vulnerability exists in the Codecs component of Google Chrome versions prior to 146.0.7680.178. This flaw could potentially enable remote attackers to manipulate the browser's behavior through crafted HTML pages, resulting in arbitrary read/write capabilities. Users and organizations utilizing unpatched versions may be at risk of exploitation, making it crucial to update to the latest version.

Affected Version(s)

Chrome 146.0.7680.178

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.