Junglewise Threat Intelligence

CVE-2026-5902: Google Chrome race condition in Media component

CVE-2026-5902 · Severity: critical · CVSS 9.8 · Published 2026-04-08

Technologies: Apple macOS, Microsoft Windows, Google Chrome, Linux Kernel. Vendors: Apple, Microsoft, Google, Linux.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its media handling component could allow an attacker who has already partially compromised the browser to corrupt media stream data. This could lead to further instability or be used as part of a more complex attack to gain control over the user's device.

Technical details

A race condition vulnerability (CWE-362) exists in the Media component of Google Chrome for Android. The flaw is reachable if an attacker has already achieved code execution within the sandboxed renderer process. By enticing a user to visit a specially crafted HTML page, the attacker can exploit improper synchronization to corrupt media stream metadata. While Chromium classifies the severity as Low due to the prerequisite of a renderer compromise, CISA-ADP has assigned a Critical CVSS score of 9.8. The issue is resolved in version 147.0.7727.55.

Affected products

  • Google Chrome prior to 147.0.7727.55

Timeline

  • 2026-02-10: other: Vulnerability reported to Chromium
  • 2026-04-07: patched: Stable channel update released
  • 2026-04-08: disclosed: CVE published

References

Related threats