Junglewise Threat Intelligence

CVE-2026-5893: Google Chrome race condition in V8 engine

CVE-2026-5893 · Severity: medium · CVSS 6.8 · Published 2026-04-08

Technologies: Apple macOS, Microsoft Windows, Google Chrome, Linux Kernel. Vendors: Apple, Microsoft, Google, Linux.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its V8 engine could allow a remote attacker to corrupt the browser's memory if a user visits a specially crafted website. This could lead to unauthorized access to information or the ability to modify data within the browser session.

Technical details

A race condition (CWE-362) exists in the V8 JavaScript engine component of Google Chrome. The vulnerability is triggered when the browser processes a specially crafted HTML page, leading to improper synchronization of shared resources. An unauthenticated remote attacker can exploit this flaw to cause heap corruption. Successful exploitation requires user interaction (visiting a malicious site) and has a high attack complexity due to the nature of the race condition. The impact includes potential loss of confidentiality and integrity. The issue is resolved in Chrome version 147.0.7727.55.

Affected products

  • Google Chrome versions prior to 147.0.7727.55

Timeline

  • 2026-02-26: disclosed: Reported to Chromium by QYmag1c
  • 2026-04-07: patched: Chrome 147.0.7727.55 promoted to stable channel
  • 2026-04-08: advisory: NVD publication date

References

Related threats