
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5866 is a use-after-free vulnerability in the Media component of Google Chrome that allows a remote attacker to execute arbitrary code inside the Chrome sandbox via a crafted HTML page. It affects all versions of Google Chrome prior to 147.0.7727.55 on Windows, Mac, and Linux. The vulnerability was reported by researcher c6eed09fc8b174b0f3eebedcceb1e792 on March 13, 2026, and publicly disclosed with the Chrome 147 stable channel release on April 7–8, 2026. It carries a CVSS v3.1 base score of 8.8 (High) and is rated High severity by the Chromium security team (Chrome Releases, GitHub Advisory).
The vulnerability is classified as CWE-416 (Use After Free), occurring in Chrome's Media component (Chromium issue #492218537). A use-after-free condition arises when memory associated with a media object is freed but a dangling pointer to that memory is subsequently accessed, allowing an attacker to potentially control the freed memory region and redirect execution flow. Exploitation requires a victim to visit a specially crafted HTML page, which triggers the memory corruption in the Media subsystem. The attack vector is network-based with low complexity and no privileges required, though user interaction (visiting the malicious page) is necessary (Chrome Releases, GitHub Advisory).
Successful exploitation allows a remote attacker to execute arbitrary code within the Chrome sandbox environment, resulting in high confidentiality, integrity, and availability impact within the sandboxed process. An attacker could access sensitive data processed by the browser, modify content, or disrupt browser functionality. While the sandbox limits direct host OS compromise, a sandbox escape chained with this vulnerability could lead to full system compromise; exploitation alone is constrained to the renderer process (GitHub Advisory, Chrome Releases).
HTMLMediaElement) to cause a media object to be freed while a reference to it remains accessible.cmd.exe, /bin/sh, powershell.exe); Chrome renderer processes consuming abnormally high memory or crashing repeatedly.chrome_debug.log) showing heap corruption or access violation errors in media-related stack frames.Google has released Chrome 147.0.7727.55 (Linux) and 147.0.7727.55/56 (Windows/Mac) which contain the fix for this vulnerability. Users and administrators should immediately update Google Chrome to version 147.0.7727.55 or later via the browser's built-in update mechanism (Settings → Help → About Google Chrome). As a temporary workaround prior to patching, users should avoid visiting untrusted or suspicious websites. Microsoft Edge (Chromium-based) users should also apply the corresponding Edge update addressing this CVE (Chrome Releases, Microsoft MSRC).
Security news outlets including GBHackers, CyberSecurityNews, and Cryptika covered the Chrome 147 update, highlighting the multiple high-severity vulnerabilities patched in this release, including CVE-2026-5866. The SANS Internet Storm Center also noted the update in their diary (ISC diary #32898). The broader security community observed that the Chrome 147 release addressed an unusually large number of vulnerabilities (60+), with two Critical-rated WebML flaws drawing particular attention alongside the High-severity use-after-free issues (Chrome Releases).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."