
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5872 is a use-after-free vulnerability in the Blink rendering engine of Google Chrome that allows a remote attacker to execute arbitrary code inside the Chrome sandbox via a crafted HTML page. It affects Google Chrome versions prior to 147.0.7727.55 and Microsoft Edge (Chromium-based). The vulnerability was reported by Google on 2026-03-25 (Chromium issue #496281816) and publicly disclosed on 2026-04-08 when Chrome 147.0.7727.55 was released. It carries a CVSS v3.1 base score of 8.8 (High) (Chrome Releases, GitHub Advisory).
The vulnerability is classified as CWE-416 (Use After Free), occurring within Chrome's Blink rendering engine — the component responsible for parsing and rendering HTML, CSS, and DOM content. A use-after-free condition arises when memory that has been freed is subsequently referenced, potentially allowing an attacker to control the freed memory region and redirect execution flow. Exploitation requires a victim to visit a specially crafted HTML page, after which the attacker can achieve arbitrary code execution within the Chrome sandbox. Full technical details and bug specifics remain restricted pending broad user adoption of the patch (Chrome Releases, GitHub Advisory).
Successful exploitation allows a remote attacker to execute arbitrary code within the Chrome sandbox environment, with high impact to confidentiality, integrity, and availability of the affected browser process. While the sandbox limits direct host OS access, sandbox escape via a chained vulnerability could lead to full system compromise, data theft, or further lateral movement. All users running Google Chrome prior to 147.0.7727.55 on Windows, Mac, and Linux, as well as Microsoft Edge (Chromium-based), are at risk (Chrome Releases, GitHub Advisory).
Users and organizations should immediately update Google Chrome to version 147.0.7727.55 or later (147.0.7727.55/56 on Windows/Mac, 147.0.7727.55 on Linux). Microsoft Edge (Chromium-based) users should apply the corresponding security update from Microsoft. Enabling automatic browser updates is strongly recommended to ensure timely patching. As a defense-in-depth measure, users should avoid visiting untrusted or suspicious websites, and organizations should enforce browser update policies across managed endpoints (Chrome Releases, Microsoft MSRC).
The Chrome 147 update was covered by several cybersecurity news outlets including GBHackers and CyberSecurityNews, which highlighted the broader set of 60+ vulnerabilities patched in this release, including two critical WebML flaws alongside CVE-2026-5872. The SANS Internet Storm Center also noted the release in their diary. Community reaction was generally focused on the scale of the Chrome 147 patch batch rather than this specific CVE, given the absence of active exploitation. Downstream Linux distributions including Debian, openSUSE, and Fedora issued their own Chromium security advisories incorporating this fix (Chrome Releases).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."