CVE-2026-5859
vulnerability analysis and mitigation

Overview

CVE-2026-5859 is a critical integer overflow vulnerability in the WebML component of Google Chrome that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. It was reported anonymously on March 19, 2026, and publicly disclosed on April 7–8, 2026, as part of the Chrome 147 stable channel update. All Google Chrome versions prior to 147.0.7727.55 are affected, as is Microsoft Edge (Chromium-based). The vulnerability carries a CVSS v3.1 base score of 8.8 (High), though Google's internal Chromium severity rating is Critical (Chrome Releases, GitHub Advisory).

Technical details

The root cause is an integer overflow (CWE-472 — External Control of Assumed-Immutable Web Parameter) in Chrome's WebML subsystem, which implements browser-native machine learning inference capabilities. When processing a specially crafted HTML page, arithmetic operations on attacker-influenced values overflow their integer bounds, leading to heap corruption that can potentially be leveraged for arbitrary code execution. Exploitation requires no authentication and no special privileges, but does require user interaction — specifically, a victim visiting a malicious webpage. The Chromium issue tracker entry is #494158331, though full technical details remain restricted pending broad patch deployment (Chrome Releases, GitHub Advisory).

Impact

Successful exploitation can result in high impact to confidentiality, integrity, and availability of the affected system. An attacker who tricks a user into visiting a malicious webpage could achieve remote code execution within the Chrome renderer process, potentially enabling data theft, installation of malware, or further lateral movement depending on sandbox escape capabilities. The vulnerability affects all desktop platforms (Windows, Mac, Linux) running unpatched Chrome, as well as Chromium-based Microsoft Edge (Chrome Releases, GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify targets running Google Chrome versions prior to 147.0.7727.55 or unpatched Chromium-based Edge on Windows, Mac, or Linux.
  2. Craft malicious HTML page: Develop an HTML page containing JavaScript or WebML API calls that trigger the integer overflow in Chrome's WebML component by supplying carefully crafted input values that cause arithmetic bounds to be exceeded.
  3. Deliver the payload: Host the malicious page on an attacker-controlled server and lure the victim to visit it via phishing email, malicious advertisement, or compromised website.
  4. Trigger heap corruption: When the victim's browser processes the crafted WebML operations, the integer overflow causes heap memory corruption in the renderer process.
  5. Achieve code execution: Leverage the heap corruption to gain control of execution flow within the Chrome renderer sandbox, potentially chaining with a sandbox escape for full system compromise (Chrome Releases, GitHub Advisory).

Indicators of compromise

  • Network: Unexpected outbound connections from the browser process to unknown external IPs following visits to unfamiliar or suspicious websites; unusual DNS lookups initiated by the Chrome process.
  • Process: Anomalous child processes spawned by chrome.exe or chromium (e.g., cmd.exe, powershell.exe, bash, curl) that are not typical browser subprocesses; renderer processes consuming abnormally high memory.
  • Logs: Browser crash reports or crash dumps referencing WebML-related memory corruption; Windows Event Logs showing unexpected process creation events parented to Chrome.
  • File System: Unexpected files written to user temp directories or AppData by the Chrome process; new scheduled tasks or persistence mechanisms created shortly after browser activity.

Mitigation and workarounds

The primary remediation is to update Google Chrome to version 147.0.7727.55 or later on all platforms (Windows, Mac, Linux), which was released on April 7, 2026 (Chrome Releases). Microsoft Edge (Chromium-based) users should apply the corresponding Microsoft patch released April 11, 2026 (Microsoft MSRC). As a temporary workaround prior to patching, organizations should consider restricting user access to untrusted or unknown websites and educating users to avoid clicking unsolicited links. ChromeOS users should apply the corresponding ChromeOS stable channel update released in late April 2026.

Community reactions

The Chrome 147 update received broad media coverage given that it patched 60 security vulnerabilities, including two Critical-rated WebML flaws (CVE-2026-5858 and CVE-2026-5859). Forbes reported a critical update alert for Chrome's estimated 3.5 billion users, and outlets including Heise, PCWorld, GBHackers, and CyberSecurityNews covered the release (Forbes, Heise). The $43,000 bug bounty awarded for this vulnerability was noted as a signal of its severity. Social media discussion on Mastodon, Bluesky, and LinkedIn highlighted the critical rating and urged immediate patching.

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management