Executive brief
A vulnerability in Google Chrome's WebML component could allow an attacker to access sensitive information from the browser's memory. This occurs when a user visits a specially crafted website, potentially leading to the exposure of private data from other open tabs or browser processes. Users should update to the latest version of Chrome to mitigate this risk.
Technical details
A heap-based buffer overflow vulnerability (CWE-122) exists in the WebML component of Google Chrome. The flaw is triggered when the browser processes a specially crafted HTML page, allowing a remote, unauthenticated attacker to read sensitive information from the process memory. This is a cross-platform issue affecting Windows, Mac, and Linux versions of the browser. The vulnerability was addressed in Chrome version 147.0.7727.55. Exploitation requires user interaction (visiting a malicious site).
Affected products
- Google Chrome prior to 147.0.7727.55
Timeline
- 2026-03-18: disclosed: Reported to Chromium project by researcher c6eed09fc8b174b0f3eebedcceb1e792
- 2026-04-07: patched: Fixed in Chrome 147.0.7727.55 stable channel release
- 2026-04-08: advisory: NVD published CVE-2026-5869