Junglewise Threat Intelligence

CVE-2026-5883: Google Chrome use after free in Media

CVE-2026-5883 · Severity: high · CVSS 8.8 · Published 2026-04-08

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in Google Chrome's media handling component. By tricking a user into visiting a specially crafted website, a remote attacker could execute unauthorized code on the user's computer. While this code execution is restricted by the browser's security sandbox, it could still lead to data theft or be used as part of a larger attack to compromise the entire system.

Technical details

A use-after-free (UAF) vulnerability exists in the Media component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during the processing of media content within a crafted HTML page. An unauthenticated remote attacker can exploit this by enticing a user to visit a malicious website, leading to arbitrary code execution within the renderer process sandbox. The vulnerability is addressed in Google Chrome version 147.0.7727.55.

Affected products

  • Google Chrome prior to 147.0.7727.55

Timeline

  • 2026-02-09: other: Reported to Chromium by sherkito
  • 2026-04-07: patched: Fixed in Chrome 147.0.7727.55 stable release
  • 2026-04-08: disclosed: CVE published

References