Junglewise Threat Intelligence

CVE-2026-5885: Google Chrome improper input validation in WebML

CVE-2026-5885 · Severity: medium · CVSS 6.5 · Published 2026-04-08

Technologies: Apple macOS, Microsoft Windows, Google Chrome, Linux Kernel. Vendors: Apple, Microsoft, Google, Linux.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its WebML component could allow a remote attacker to access sensitive information from the computer's memory if a user visits a specially crafted website. This could lead to the exposure of private data handled by the browser process.

Technical details

An improper input validation vulnerability (CWE-20) exists in the WebML component of Google Chrome for Windows. The flaw allows a remote attacker to trigger an information disclosure by enticing a user to visit a maliciously crafted HTML page. Successful exploitation enables the attacker to read potentially sensitive data from the browser's process memory. The issue is addressed in Chrome version 147.0.7727.55 and later.

Affected products

  • Google Chrome prior to 147.0.7727.55

Timeline

  • 2026-02-17: disclosed: Reported by Bryan Bernhart
  • 2026-04-07: patched: Fixed in Chrome 147.0.7727.55 stable channel update
  • 2026-04-08: advisory: NVD publication date

References

Related threats