
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5860 is a use-after-free vulnerability in the WebRTC component of Google Chrome that allows a remote attacker to execute arbitrary code inside the Chrome sandbox via a crafted HTML page. The vulnerability was reported by researcher c6eed09fc8b174b0f3eebedcceb1e792 on February 22, 2026, and publicly disclosed on April 8, 2026, as part of the Chrome 147 stable channel release. It affects all Google Chrome versions prior to 147.0.7727.55, as well as Microsoft Edge (Chromium-based) builds based on the same codebase. Google assigned it a Chromium security severity of High, with a CVSS v3.1 base score of 8.8 (High) (Chrome Releases, GitHub Advisory).
The vulnerability is classified as CWE-416 (Use After Free), occurring within Chrome's WebRTC implementation — the browser subsystem responsible for real-time audio, video, and data communication. A use-after-free condition arises when a memory object in the WebRTC component is freed but a dangling pointer to that memory is subsequently accessed, allowing an attacker to potentially control the freed memory region and redirect execution flow. Exploitation requires a victim to visit a specially crafted HTML page, which can trigger the vulnerable WebRTC code path with low attack complexity and no required privileges. The bug was tracked internally as Chromium issue 486495143 and earned a $11,000 bug bounty reward (Chrome Releases, GitHub Advisory).
Successful exploitation allows a remote attacker to execute arbitrary code within the Chrome sandbox, which can lead to unauthorized access to sensitive browser data, code execution within the renderer process, and potential compromise of the affected system if combined with a sandbox escape. The vulnerability carries high confidentiality, integrity, and availability impact ratings, meaning an attacker could read sensitive data, modify browser state, or cause crashes. While the sandbox boundary limits the immediate blast radius, this class of vulnerability is frequently chained with sandbox escapes in targeted attack scenarios (GitHub Advisory, Chrome Releases).
chrome.exe, chrome on Linux/Mac) spawning unexpected child processes or exhibiting anomalous memory usage; crash dumps generated by the Chrome renderer process referencing WebRTC-related stack frames.Google has released Chrome 147.0.7727.55 (Linux) and 147.0.7727.55/56 (Windows/Mac) which addresses CVE-2026-5860. Users should update Chrome immediately via the browser's built-in update mechanism (Settings → Help → About Google Chrome). Microsoft Edge users should apply the corresponding Chromium-based update from Microsoft. As an interim measure, organizations should restrict user access to untrusted or unknown websites and consider enabling enhanced security features or site isolation policies. No configuration-only workaround is available; patching is the only definitive remediation (Chrome Releases, Microsoft MSRC).
The Chrome 147 update was covered by several cybersecurity news outlets, including GBHackers and CyberSecurityNews, which highlighted the batch of 60+ vulnerabilities patched in this release, including two critical WebML flaws and multiple high-severity issues (GBHackers, CyberSecurityNews). The Hacker News included the Chrome update in its weekly security recap. The SANS Internet Storm Center also noted the release in its diary. Community reaction was generally focused on the broader Chrome 147 update rather than CVE-2026-5860 specifically, given the large number of fixes included. No notable individual researcher commentary specific to this CVE has been publicly identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."