Loading
WebM libvpx (aka the VP8 Codec SDK) before 0.9.5, as used in Google Chrome before 7.0.517.44, allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via invalid frames.
Use CWE-190, Google vendor hub and Chrome product page to widen CVE-2010-4203 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-6920, CVE-2026-6919 and CVE-2026-6363 for nearby disclosures in the same product family. Additional editorial context is available in The Weekly Cybersecurity Brief: February 27th, 2026.