CVE-2026-13018
MEDIUM
NVD
CVSS Score
4.3
Severity
MEDIUM
Published
Sep 28, 2026
Vendor
unknown
Description
Insufficient validation of untrusted input in Codecs in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially perform out of bounds memory access via a crafted video file. (Chromium security severity: Low)