Google and Microsoft disclosed CVE-2026-7933 on May 6, 2026, as a medium-severity Chromium WebCodecs out-of-bounds read flaw fixed in Google Chrome before version 148.0.7778.96 and tracked by Microsoft for Chromium-based Edge users through MSRC. The bug is not a headline-grabbing browser...
Google and Microsoft disclosed CVE-2026-7982 on May 6, 2026, as a medium-severity Chromium WebCodecs flaw fixed in Google Chrome before version 148.0.7778.96, allowing a remote attacker to expose potentially sensitive process memory through a crafted HTML page. That is the plain version; the...
Chromium’s CVE-2026-5280 is another reminder that browser security is still dominated by memory-safety failures in code paths most users never think about. The flaw is a use-after-free in WebCodecs affecting Google Chrome prior to 146.0.7680.178, and Google says a remote attacker could exploit...