Executive brief
A critical vulnerability exists in Google Chrome's WebML component, which is used for machine learning tasks within the browser. An attacker could exploit this flaw by tricking a user into visiting a specially crafted website, potentially leading to a complete compromise of the user's browser session or the underlying system. This could result in the theft of sensitive data, unauthorized access to accounts, or the installation of malicious software.
Technical details
An integer overflow vulnerability exists in the WebML (Web Machine Learning) component of Google Chrome. The flaw is triggered when the browser processes a specially crafted HTML page, leading to heap corruption. This is a remote, unauthenticated attack vector that requires minimal user interaction (visiting a malicious URL). Successful exploitation could allow an attacker to achieve arbitrary code execution within the context of the browser's sandbox. The vulnerability was addressed in Chrome version 147.0.7727.55.
Affected products
- Google Chrome prior to 147.0.7727.55
Timeline
- 2026-03-19: other: Vulnerability reported to Chromium project
- 2026-04-07: patched: Stable channel update released for desktop
- 2026-04-08: disclosed: Public disclosure of CVE-2026-5859