CVE-2026-5872
vulnerability analysis and mitigation

Overview

CVE-2026-5872 is a use-after-free vulnerability in the Blink rendering engine of Google Chrome that allows a remote attacker to execute arbitrary code inside the Chrome sandbox via a crafted HTML page. It affects Google Chrome versions prior to 147.0.7727.55 and Microsoft Edge (Chromium-based). The vulnerability was reported by Google on 2026-03-25 (Chromium issue #496281816) and publicly disclosed on 2026-04-08 when Chrome 147.0.7727.55 was released. It carries a CVSS v3.1 base score of 8.8 (High) (Chrome Releases, GitHub Advisory).

Technical details

The vulnerability is classified as CWE-416 (Use After Free), occurring within Chrome's Blink rendering engine — the component responsible for parsing and rendering HTML, CSS, and DOM content. A use-after-free condition arises when memory that has been freed is subsequently referenced, potentially allowing an attacker to control the freed memory region and redirect execution flow. Exploitation requires a victim to visit a specially crafted HTML page, after which the attacker can achieve arbitrary code execution within the Chrome sandbox. Full technical details and bug specifics remain restricted pending broad user adoption of the patch (Chrome Releases, GitHub Advisory).

Impact

Successful exploitation allows a remote attacker to execute arbitrary code within the Chrome sandbox environment, with high impact to confidentiality, integrity, and availability of the affected browser process. While the sandbox limits direct host OS access, sandbox escape via a chained vulnerability could lead to full system compromise, data theft, or further lateral movement. All users running Google Chrome prior to 147.0.7727.55 on Windows, Mac, and Linux, as well as Microsoft Edge (Chromium-based), are at risk (Chrome Releases, GitHub Advisory).

Mitigation and workarounds

Users and organizations should immediately update Google Chrome to version 147.0.7727.55 or later (147.0.7727.55/56 on Windows/Mac, 147.0.7727.55 on Linux). Microsoft Edge (Chromium-based) users should apply the corresponding security update from Microsoft. Enabling automatic browser updates is strongly recommended to ensure timely patching. As a defense-in-depth measure, users should avoid visiting untrusted or suspicious websites, and organizations should enforce browser update policies across managed endpoints (Chrome Releases, Microsoft MSRC).

Community reactions

The Chrome 147 update was covered by several cybersecurity news outlets including GBHackers and CyberSecurityNews, which highlighted the broader set of 60+ vulnerabilities patched in this release, including two critical WebML flaws alongside CVE-2026-5872. The SANS Internet Storm Center also noted the release in their diary. Community reaction was generally focused on the scale of the Chrome 147 patch batch rather than this specific CVE, given the absence of active exploitation. Downstream Linux distributions including Debian, openSUSE, and Fedora issued their own Chromium security advisories incorporating this fix (Chrome Releases).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management