
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5870 is a high-severity integer overflow vulnerability in the Skia graphics rendering engine used by Google Chrome and Microsoft Edge (Chromium-based). It was reported by Google on 2026-03-23 and publicly disclosed on 2026-04-08 as part of the Chrome 147 stable channel release. The vulnerability affects all versions of Google Chrome prior to 147.0.7727.55 and Microsoft Edge Chromium prior to its corresponding patched release. It carries a CVSS v3.1 base score of 8.8 (High) (Chrome Release, GitHub Advisory).
The vulnerability is classified under CWE-190 (Integer Overflow or Wraparound) and CWE-472 (External Control of Assumed-Immutable Web Parameter), residing in Skia, the open-source 2D graphics library that Chrome uses for rendering. An integer overflow occurs when a calculation in Skia produces a value exceeding the representable range, potentially leading to memory corruption that can be leveraged for arbitrary code execution. The attack vector is network-based and requires no privileges, but does require user interaction — specifically, a victim visiting a crafted HTML page. The Chromium issue tracker references bug ID 495534710, though full technical details remain restricted pending broad patch deployment (Chrome Release, GitHub Advisory).
Successful exploitation allows a remote attacker to execute arbitrary code inside the Chrome or Edge sandbox via a crafted HTML page, with high impact on confidentiality, integrity, and availability. While sandbox containment limits the immediate blast radius, sandbox escapes chained with this vulnerability could lead to full system compromise. The vulnerability affects all desktop platforms (Windows, Mac, Linux) running unpatched Chrome or Edge Chromium, representing a broad attack surface given the ubiquity of these browsers (GitHub Advisory, Chrome Release).
chrome.exe, msedge.exe, or their Linux/macOS equivalents (e.g., cmd.exe, powershell.exe, /bin/sh, curl, wget); renderer processes consuming abnormally high memory.Update Google Chrome to version 147.0.7727.55 or later on all platforms (Windows, Mac, Linux); Chrome typically auto-updates but administrators should verify deployment via enterprise management tools. Microsoft Edge Chromium users should apply the corresponding Microsoft security update available via the Microsoft Security Response Center (Microsoft MSRC). Linux distributions including Debian, openSUSE, and Fedora have also released updated Chromium packages. As an interim measure, restrict users from visiting untrusted or unknown websites and consider enabling enhanced browser security policies. No configuration-based workaround is available that fully mitigates the vulnerability without patching.
The Chrome 147 update was covered by security news outlets including GBHackers and CyberSecurityNews, which highlighted the batch of critical and high-severity vulnerabilities patched in this release. The SANS Internet Storm Center also noted the update in their diary. Community reaction focused on the breadth of the Chrome 147 security release (60+ vulnerabilities) rather than CVE-2026-5870 specifically, given the absence of active exploitation. No notable individual researcher commentary specific to this CVE has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."