
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5859 is a critical integer overflow vulnerability in the WebML component of Google Chrome that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. It was reported anonymously on March 19, 2026, and publicly disclosed on April 7–8, 2026, as part of the Chrome 147 stable channel update. All Google Chrome versions prior to 147.0.7727.55 are affected, as is Microsoft Edge (Chromium-based). The vulnerability carries a CVSS v3.1 base score of 8.8 (High), though Google's internal Chromium severity rating is Critical (Chrome Releases, GitHub Advisory).
The root cause is an integer overflow (CWE-472 — External Control of Assumed-Immutable Web Parameter) in Chrome's WebML subsystem, which implements browser-native machine learning inference capabilities. When processing a specially crafted HTML page, arithmetic operations on attacker-influenced values overflow their integer bounds, leading to heap corruption that can potentially be leveraged for arbitrary code execution. Exploitation requires no authentication and no special privileges, but does require user interaction — specifically, a victim visiting a malicious webpage. The Chromium issue tracker entry is #494158331, though full technical details remain restricted pending broad patch deployment (Chrome Releases, GitHub Advisory).
Successful exploitation can result in high impact to confidentiality, integrity, and availability of the affected system. An attacker who tricks a user into visiting a malicious webpage could achieve remote code execution within the Chrome renderer process, potentially enabling data theft, installation of malware, or further lateral movement depending on sandbox escape capabilities. The vulnerability affects all desktop platforms (Windows, Mac, Linux) running unpatched Chrome, as well as Chromium-based Microsoft Edge (Chrome Releases, GitHub Advisory).
chrome.exe or chromium (e.g., cmd.exe, powershell.exe, bash, curl) that are not typical browser subprocesses; renderer processes consuming abnormally high memory.The primary remediation is to update Google Chrome to version 147.0.7727.55 or later on all platforms (Windows, Mac, Linux), which was released on April 7, 2026 (Chrome Releases). Microsoft Edge (Chromium-based) users should apply the corresponding Microsoft patch released April 11, 2026 (Microsoft MSRC). As a temporary workaround prior to patching, organizations should consider restricting user access to untrusted or unknown websites and educating users to avoid clicking unsolicited links. ChromeOS users should apply the corresponding ChromeOS stable channel update released in late April 2026.
The Chrome 147 update received broad media coverage given that it patched 60 security vulnerabilities, including two Critical-rated WebML flaws (CVE-2026-5858 and CVE-2026-5859). Forbes reported a critical update alert for Chrome's estimated 3.5 billion users, and outlets including Heise, PCWorld, GBHackers, and CyberSecurityNews covered the release (Forbes, Heise). The $43,000 bug bounty awarded for this vulnerability was noted as a signal of its severity. Social media discussion on Mastodon, Bluesky, and LinkedIn highlighted the critical rating and urged immediate patching.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."