
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5858 is a heap buffer overflow vulnerability in the WebML component of Google Chrome that allows a remote attacker to execute arbitrary code via a crafted HTML page. The vulnerability was reported by researcher c6eed09fc8b174b0f3eebedcceb1e792 on 2026-03-17 and publicly disclosed on 2026-04-08 as part of the Chrome 147 stable channel release. It affects all versions of Google Chrome prior to 147.0.7727.55, as well as Microsoft Edge (Chromium-based). It carries a CVSS v3.1 base score of 8.8 (High), rated Critical by Chromium's internal severity scale, and earned a $43,000 bug bounty reward (Chrome Release Blog, GitHub Advisory).
The root cause is a heap-based buffer overflow (CWE-122) in Chrome's WebML subsystem, likely compounded by incorrect calculation of buffer size (CWE-131) when processing machine learning model data or operations within the browser. An attacker can exploit this by hosting a specially crafted HTML page that triggers malformed WebML operations, causing the browser to write beyond the bounds of a heap-allocated buffer. Exploitation requires user interaction — specifically, a victim must visit the attacker-controlled page — but requires no special privileges or authentication. The Chromium issue tracker entry (ID 493319454) is currently restricted pending broad user adoption of the patch (Chrome Release Blog, GitHub Advisory).
Successful exploitation allows a remote attacker to execute arbitrary code with the privileges of the Chrome browser process on the victim's system, potentially leading to complete system compromise. This could result in unauthorized data access (high confidentiality impact), data modification or malware installation (high integrity impact), and system disruption (high availability impact). The vulnerability could serve as an initial access vector enabling lateral movement within an enterprise environment if the compromised browser session has access to internal resources or credentials (GitHub Advisory, Red Hat Bugzilla).
cmd.exe, powershell.exe, /bin/sh, curl, wget); unusual process trees originating from chrome.exe or chromium.Google has released Chrome 147.0.7727.55 (Linux) and 147.0.7727.55/56 (Windows/Mac) which addresses this vulnerability. Users should immediately update Google Chrome via the built-in update mechanism (Settings → Help → About Google Chrome) or by downloading the latest version from the official site. Microsoft Edge (Chromium-based) and other Chromium-derived browsers should also be updated to their corresponding patched releases. Enabling automatic browser updates is strongly recommended to prevent future exposure. As a temporary measure, organizations may consider restricting access to untrusted external websites via web proxy policies until patching is complete (Chrome Release Blog, Microsoft MSRC).
The Chrome 147 update received broad media coverage given the scale of Chrome's user base (estimated 3.5 billion users), with outlets including Forbes, Heise, PCWorld, and GBHackers reporting on the critical WebML flaws. Forbes specifically highlighted the update as a critical alert for Chrome users (Forbes). Heise noted the update closed 60 security vulnerabilities including two critical ones (Heise). The F5 Labs weekly threat bulletin and SANS ISC diary also flagged the vulnerability for enterprise defenders. The $43,000 bug bounty payout for CVE-2026-5858 was noted as a significant reward, reflecting the severity of the finding (Chrome Release Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."