Junglewise Threat Intelligence

CVE-2026-5915: Google Chrome out of bounds memory write in WebML

CVE-2026-5915 · Severity: high · CVSS 8.1 · Published 2026-04-08

Technologies: Apple macOS, Microsoft Windows, Google Chrome, Linux Kernel. Vendors: Apple, Microsoft, Google, Linux.

Executive brief

A vulnerability in Google Chrome's WebML component could allow a remote attacker to interfere with the browser's memory. By tricking a user into visiting a specially crafted website, an attacker could potentially cause the browser to crash or execute unauthorized actions. This affects users on Windows, Mac, and Linux systems using older versions of the Chrome browser.

Technical details

An out-of-bounds (OOB) memory write vulnerability exists in the WebML component of Google Chrome due to insufficient validation of untrusted input. A remote, unauthenticated attacker can exploit this by enticing a user to visit a maliciously crafted HTML page. Successful exploitation allows the attacker to perform an out-of-bounds write, which can lead to memory corruption, application instability, or potentially arbitrary code execution within the browser's sandbox. The issue is addressed in Google Chrome version 147.0.7727.55.

Affected products

  • Google Chrome prior to 147.0.7727.55

Timeline

  • 2026-03-20: disclosed: Reported to Chromium by ningxin.hu@intel.com
  • 2026-04-07: patched: Chrome 147.0.7727.55 released to stable channel
  • 2026-04-08: advisory

References

Related threats