Junglewise Threat Intelligence

CVE-2026-5913: Google Chrome out of bounds read in Blink

CVE-2026-5913 · Severity: high · CVSS 8.1 · Published 2026-04-08

Technologies: Apple macOS, Microsoft Windows, Google Chrome, Linux Kernel. Vendors: Apple, Microsoft, Google, Linux.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its rendering engine, Blink, could allow a remote attacker to read sensitive information from the computer's memory if a user visits a specially crafted website. This could lead to the exposure of private data or help an attacker bypass other security protections.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in the Blink rendering engine of Google Chrome prior to version 147.0.7727.55. The flaw is triggered when the browser processes a specially crafted HTML page, allowing a remote attacker to read memory outside of the intended buffer. While Chromium developers classified the internal severity as Low, CISA-ADP has assigned a CVSS score of 8.1 (High), noting that the vulnerability can lead to significant information disclosure. The issue is resolved in Chrome version 147.0.7727.55 and later.

Affected products

  • Google Chrome prior to 147.0.7727.55

Timeline

  • 2026-02-24: disclosed: Reported by Vitaly Simonovich
  • 2026-04-07: patched: Fixed in Chrome 147.0.7727.55 stable channel update
  • 2026-04-08: advisory: NVD publication date

References

Related threats