CVE-2026-5870
vulnerability analysis and mitigation

Overview

CVE-2026-5870 is a high-severity integer overflow vulnerability in the Skia graphics rendering engine used by Google Chrome and Microsoft Edge (Chromium-based). It was reported by Google on 2026-03-23 and publicly disclosed on 2026-04-08 as part of the Chrome 147 stable channel release. The vulnerability affects all versions of Google Chrome prior to 147.0.7727.55 and Microsoft Edge Chromium prior to its corresponding patched release. It carries a CVSS v3.1 base score of 8.8 (High) (Chrome Release, GitHub Advisory).

Technical details

The vulnerability is classified under CWE-190 (Integer Overflow or Wraparound) and CWE-472 (External Control of Assumed-Immutable Web Parameter), residing in Skia, the open-source 2D graphics library that Chrome uses for rendering. An integer overflow occurs when a calculation in Skia produces a value exceeding the representable range, potentially leading to memory corruption that can be leveraged for arbitrary code execution. The attack vector is network-based and requires no privileges, but does require user interaction — specifically, a victim visiting a crafted HTML page. The Chromium issue tracker references bug ID 495534710, though full technical details remain restricted pending broad patch deployment (Chrome Release, GitHub Advisory).

Impact

Successful exploitation allows a remote attacker to execute arbitrary code inside the Chrome or Edge sandbox via a crafted HTML page, with high impact on confidentiality, integrity, and availability. While sandbox containment limits the immediate blast radius, sandbox escapes chained with this vulnerability could lead to full system compromise. The vulnerability affects all desktop platforms (Windows, Mac, Linux) running unpatched Chrome or Edge Chromium, representing a broad attack surface given the ubiquity of these browsers (GitHub Advisory, Chrome Release).

Exploitation steps

  1. Reconnaissance: Identify targets running Google Chrome versions prior to 147.0.7727.55 or Microsoft Edge Chromium prior to the patched version, using browser fingerprinting techniques on a malicious or compromised website.
  2. Craft malicious HTML page: Develop an HTML page containing specially crafted content (e.g., complex SVG, canvas, or CSS rendering operations) designed to trigger the integer overflow condition in Skia's rendering pipeline.
  3. Deliver payload: Host the malicious page on an attacker-controlled server or inject it into a legitimate site via a watering hole or ad network. Lure the victim to visit the page via phishing, malvertising, or social engineering.
  4. Trigger integer overflow: When the victim's browser renders the page, the crafted content causes an integer overflow in Skia, resulting in memory corruption (e.g., heap overflow or out-of-bounds write).
  5. Achieve code execution: Leverage the memory corruption to redirect execution flow and run arbitrary code within the Chrome renderer sandbox, potentially chaining with a sandbox escape for full system access (Chrome Release, GitHub Advisory).

Indicators of compromise

  • Network: Unexpected outbound connections from the browser process to unknown external IPs or domains shortly after visiting an unfamiliar website; unusual DNS lookups initiated by the Chrome or Edge process.
  • Process: Unusual child processes spawned by chrome.exe, msedge.exe, or their Linux/macOS equivalents (e.g., cmd.exe, powershell.exe, /bin/sh, curl, wget); renderer processes consuming abnormally high memory.
  • Logs: Browser crash reports or unexpected renderer process terminations logged in Chrome's crash reporter or Windows Event Logs around the time of a suspicious page visit.
  • File System: Unexpected files written to the user's temp directory or browser profile directory by the browser process; new scheduled tasks or persistence mechanisms created shortly after browser activity.

Mitigation and workarounds

Update Google Chrome to version 147.0.7727.55 or later on all platforms (Windows, Mac, Linux); Chrome typically auto-updates but administrators should verify deployment via enterprise management tools. Microsoft Edge Chromium users should apply the corresponding Microsoft security update available via the Microsoft Security Response Center (Microsoft MSRC). Linux distributions including Debian, openSUSE, and Fedora have also released updated Chromium packages. As an interim measure, restrict users from visiting untrusted or unknown websites and consider enabling enhanced browser security policies. No configuration-based workaround is available that fully mitigates the vulnerability without patching.

Community reactions

The Chrome 147 update was covered by security news outlets including GBHackers and CyberSecurityNews, which highlighted the batch of critical and high-severity vulnerabilities patched in this release. The SANS Internet Storm Center also noted the update in their diary. Community reaction focused on the breadth of the Chrome 147 security release (60+ vulnerabilities) rather than CVE-2026-5870 specifically, given the absence of active exploitation. No notable individual researcher commentary specific to this CVE has been identified.

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management