Junglewise Threat Intelligence

CVE-2026-5914: Google Chrome type confusion in CSS

CVE-2026-5914 · Severity: high · CVSS 8.8 · Published 2026-04-08

Technologies: Apple macOS, Microsoft Windows, Google Chrome, Linux Kernel. Vendors: Apple, Microsoft, Google, Linux.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in how the browser handles CSS (website styling) could allow a malicious browser extension to cause memory corruption. If exploited, this could allow an attacker to compromise the user's computer or access sensitive data, though it requires the user to first install a specifically crafted malicious extension.

Technical details

A type confusion vulnerability exists in the CSS engine of Google Chrome. The flaw is triggered when the browser accesses a resource using an incompatible type (CWE-843), leading to potential heap corruption. To exploit this, an attacker must convince a user to install a malicious Chrome Extension containing a specially crafted payload. While Chromium developers rated the internal severity as 'Low', external assessments (CISA-ADP) assigned a CVSS score of 8.8, indicating a high potential impact on confidentiality, integrity, and availability if the precondition of extension installation is met. The issue is resolved in Chrome version 147.0.7727.55.

Affected products

  • Google Chrome Prior to 147.0.7727.55

Timeline

  • 2026-03-05: disclosed: Vulnerability reported to Chromium by Syn4pse
  • 2026-04-07: patched: Chrome 147.0.7727.55 released to stable channel
  • 2026-04-08: advisory: NVD publication date

References

Related threats