You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
cve-2026-7982
About this tag
CVE-2026-7982 is a medium-severity information disclosure vulnerability in Chromium's WebCodecs component, disclosed by Google and Microsoft on May 6, 2026. The flaw allows a remote attacker to expose sensitive process memory via a crafted HTML page. It was fixed in Google Chrome version 148.0.7778.96 and later. Because Chromium is the foundation for many browsers, this vulnerability also affects Microsoft Edge, Brave, Vivaldi, Opera, and enterprise Chromium builds on Windows. While not a code-execution zero-day, the bug turns a simple page visit into a potential information-leak event. Windows users should update their browsers promptly to mitigate the risk.
Google and Microsoft disclosed CVE-2026-7982 on May 6, 2026, as a medium-severity Chromium WebCodecs flaw fixed in Google Chrome before version 148.0.7778.96, allowing a remote attacker to expose potentially sensitive process memory through a crafted HTML page. That is the plain version; the...