Junglewise Threat Intelligence

CVE-2026-5870: Google Chrome integer overflow in Skia

CVE-2026-5870 · Severity: high · CVSS 8.8 · Published 2026-04-08

Technologies: Apple macOS, Microsoft Windows, Google Chrome, Linux Kernel. Vendors: Apple, Microsoft, Google, Linux.

Executive brief

Google Chrome is a widely used web browser. A security vulnerability in its graphics engine, Skia, could allow a remote attacker to execute malicious code on a user's computer if they visit a specially crafted website. While the attack is limited by the browser's security sandbox, it still poses a significant risk to data privacy and system integrity.

Technical details

An integer overflow vulnerability (CWE-190) exists in the Skia graphics library component of Google Chrome. The flaw is triggered when the browser processes a specially crafted HTML page, allowing a remote, unauthenticated attacker to achieve arbitrary code execution within the renderer process sandbox. The vulnerability was addressed in Chrome version 147.0.7727.55. Exploitation requires user interaction (visiting a malicious site) but does not require special privileges.

Affected products

  • Google Chrome prior to 147.0.7727.55

Timeline

  • 2026-03-23: disclosed: Reported by Google internal researchers
  • 2026-04-07: patched: Fixed in Chrome 147.0.7727.55 stable release
  • 2026-04-08: advisory: NVD publication date

References

Related threats