
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5869 is a heap-based buffer overflow vulnerability in the WebML component of Google Chrome that allows a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. It affects all versions of Google Chrome prior to 147.0.7727.55 on Windows, Mac, and Linux, as well as Microsoft Edge (Chromium-based). The vulnerability was reported by researcher c6eed09fc8b174b0f3eebedcceb1e792 on March 18, 2026, and publicly disclosed on April 8, 2026, when Google released Chrome 147.0.7727.55. It carries a CVSS v3.1 base score of 4.3 (Medium) per NVD, with Chromium classifying its severity as High (Chrome Release Blog, GitHub Advisory).
The vulnerability is classified as CWE-122 (Heap-based Buffer Overflow) and resides in Chrome's WebML subsystem, which implements machine learning inference capabilities within the browser. The flaw allows an out-of-bounds read from heap memory, triggered when a user visits a specially crafted HTML page that causes the WebML component to process malformed input without adequate bounds checking. Exploitation requires user interaction — specifically, a victim must navigate to an attacker-controlled or compromised web page — but requires no authentication or special privileges. The Chromium bug tracker references issue #493708165 for this vulnerability (Chrome Release Blog, GitHub Advisory).
Successful exploitation allows a remote attacker to read potentially sensitive data from the Chrome browser process memory, which may include authentication tokens, cached credentials, session cookies, or other in-memory secrets. The impact is limited to confidentiality — there is no integrity or availability impact under the NVD scoring — and the vulnerability does not provide code execution capability on its own. The scope is confined to the affected browser process, with no direct path to lateral movement, though leaked credentials could facilitate further attacks (Chrome Release Blog, GitHub Advisory).
fetch() or XMLHttpRequest), potentially exposing authentication tokens, session data, or other sensitive in-memory information (Chrome Release Blog, GitHub Advisory).navigator.ml, MLContext, MLGraph) on pages that have no legitimate reason to use machine learning features..dmp) generated in the user profile directory following visits to suspicious web pages.Google has released Chrome 147.0.7727.55 (Linux) and 147.0.7727.55/56 (Windows/Mac) which patches CVE-2026-5869 along with numerous other vulnerabilities. Users and administrators should update Chrome immediately via the browser's built-in update mechanism (Settings > Help > About Google Chrome) or through enterprise management tools. Microsoft has also issued guidance for Edge (Chromium-based) users via the MSRC advisory. As a temporary workaround prior to patching, organizations should consider blocking access to untrusted websites and disabling or restricting WebML/ML API usage via enterprise policy where feasible (Chrome Release Blog, Microsoft MSRC).
Security news outlets including GBHackers and CyberSecurityNews covered the Chrome 147 update, noting the large number of vulnerabilities patched (approximately 60) including multiple WebML flaws. The SANS Internet Storm Center also published a diary entry referencing the update. The broader security community noted the concentration of WebML-related vulnerabilities in this release cycle as notable, given that WebML is a relatively new browser API surface. No significant controversy or researcher dispute regarding the severity rating has been observed (GBHackers, CyberSecurityNews, SANS ISC).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."