
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5868 is a heap buffer overflow vulnerability in ANGLE (Almost Native Graphics Layer Engine), the graphics abstraction layer used by Google Chrome on macOS. It was reported by researcher "cinzinga" on March 16, 2026, and publicly disclosed on April 8, 2026, as part of the Chrome 147 stable channel release. The vulnerability affects Google Chrome versions prior to 147.0.7727.55 on Mac, as well as Microsoft Edge (Chromium-based). It carries a CVSS v3.1 base score of 8.8 (High) (Chrome Releases, GitHub Advisory).
The vulnerability is classified as CWE-122 (Heap-based Buffer Overflow), occurring within ANGLE, Chrome's cross-platform OpenGL ES implementation used to translate graphics calls on macOS. A heap buffer overflow arises when ANGLE processes a specially crafted HTML page containing malicious graphics or WebGL content, causing it to write beyond the bounds of a heap-allocated buffer. Exploitation requires user interaction — specifically, a victim visiting or being redirected to a malicious web page — but requires no special privileges from the attacker. The Chromium issue tracker entry is referenced as issue #493256564 (Chrome Releases, GitHub Advisory).
Successful exploitation allows a remote attacker to execute arbitrary code within the Chrome sandbox on macOS systems, with high impact on confidentiality, integrity, and availability. While execution is constrained to the browser sandbox, this represents a significant foothold that could be chained with a sandbox escape vulnerability to achieve full system compromise. The attack is network-based with low complexity, making it accessible to a broad range of threat actors targeting Mac users running unpatched Chrome or Edge Chromium (Chrome Releases, GitHub Advisory).
Google has released Chrome 147.0.7727.55 (Linux) and 147.0.7727.55/56 (Windows/Mac) which contain the fix for CVE-2026-5868. Microsoft has also released a corresponding patched version of Edge Chromium. Users should update Chrome or Edge immediately via the browser's built-in update mechanism or through enterprise patch management tools. No configuration-based workaround is available; upgrading to the patched version is the only effective remediation (Chrome Releases, Microsoft MSRC).
Security news outlets including GBHackers and CyberSecurityNews covered the Chrome 147 update, highlighting the multiple high-severity vulnerabilities patched in this release, including CVE-2026-5868. The broader security community noted the unusually large number of fixes (60+ vulnerabilities) in this release cycle. No specific researcher commentary or notable social media discussion focused exclusively on CVE-2026-5868 beyond standard patch reporting (GBHackers, CyberSecurityNews).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."