Junglewise Threat Intelligence

CVE-2026-5858: Google Chrome heap buffer overflow in WebML

CVE-2026-5858 · Severity: high · CVSS 8.8 · Published 2026-04-08

Technologies: Apple macOS, Microsoft Windows, Google Chrome, Linux Kernel. Vendors: Apple, Microsoft, Google, Linux.

Executive brief

A critical security vulnerability has been identified in the Google Chrome web browser's WebML component. By tricking a user into visiting a specially crafted website, a remote attacker could potentially take control of the user's computer or execute unauthorized commands. This issue affects users on Windows, Mac, and Linux, and has been addressed in the latest browser update.

Technical details

A heap-based buffer overflow vulnerability (CWE-122) exists in the WebML component of Google Chrome. The flaw is triggered when the browser processes a specially crafted HTML page, allowing a remote, unauthenticated attacker to overflow memory and potentially achieve arbitrary code execution. The attack requires minimal user interaction (visiting a malicious URL) and has a high impact on confidentiality, integrity, and availability. The vulnerability was patched in version 147.0.7727.55.

Affected products

  • Google Chrome prior to 147.0.7727.55

Timeline

  • 2026-03-17: disclosed: Reported to Chromium project by researcher c6eed09fc8b174b0f3eebedcceb1e792
  • 2026-04-07: patched: Fixed in Chrome 147 stable channel release
  • 2026-04-08: advisory: NVD publication date

References

Related threats