CVE-2026-5874
vulnerability analysis and mitigation

Overview

CVE-2026-5874 is a use-after-free vulnerability in the PrivateAI component of Google Chrome that can allow a remote attacker to potentially perform a sandbox escape via a crafted HTML page. The vulnerability was reported by researcher Krace on February 18, 2026, and publicly disclosed on April 8, 2026, as part of the Chrome 147 stable channel release. It affects Google Chrome versions prior to 147.0.7727.55 on Windows, Mac, and Linux, as well as Microsoft Edge (Chromium-based). Google assigned it a Chromium security severity of Medium, though its CVSS v3.1 base score is 9.6 (Critical) due to the potential for scope change and full confidentiality, integrity, and availability impact (Chrome Releases, GitHub Advisory).

Technical details

The vulnerability is classified as CWE-416 (Use After Free) and CWE-825 (Expired Pointer Dereference), arising from improper memory management in Chrome's PrivateAI component — a feature related to on-device AI processing. An attacker can exploit this flaw by crafting a malicious HTML page that triggers specific UI gestures from the victim, causing the browser to reference previously freed memory in the PrivateAI subsystem. This memory corruption condition can be leveraged to escape Chrome's sandbox, potentially enabling arbitrary code execution outside the browser's security boundary. The bug was tracked internally as Chromium issue #485397279 and carried a $11,000 bug bounty reward (Chrome Releases, GitHub Advisory, Red Hat Bugzilla).

Impact

Successful exploitation could allow a remote attacker to escape Chrome's sandbox and execute arbitrary code with the privileges of the browser process on the underlying operating system, resulting in high confidentiality, integrity, and availability impact. The scope change (S:C in CVSS) reflects that a successful exploit breaks out of the browser's security boundary, potentially granting access to the host system beyond the browser's confined environment. This could enable data theft, installation of malware, lateral movement within a network, or full system compromise depending on the attacker's post-exploitation objectives (GitHub Advisory, Red Hat Bugzilla).

Mitigation and workarounds

Google has patched this vulnerability in Chrome 147.0.7727.55 (Linux) and 147.0.7727.55/56 (Windows/Mac), released on April 7, 2026. Users should update Google Chrome immediately via the browser's built-in update mechanism (Settings → Help → About Google Chrome). Microsoft Edge users should apply the corresponding Chromium-based update through Microsoft's update channels. As a temporary measure prior to patching, organizations should educate users to avoid visiting untrusted websites and to be cautious about performing UI interactions on unfamiliar pages. Patches are also available for downstream distributions including Debian, openSUSE, and Fedora (Chrome Releases, Microsoft MSRC).

Community reactions

Security media outlets including GBHackers and BeyondMachines covered the Chrome 147 release, noting the breadth of the update (60+ vulnerabilities patched) and highlighting the two Critical-rated WebML flaws alongside CVE-2026-5874. The SANS Internet Storm Center also noted the release in its diary. Community reaction has been relatively muted given the lack of active exploitation and the Medium Chromium severity rating, despite the high CVSS score assigned by NVD. Red Hat and other Linux distribution maintainers promptly filed tracking bugs and issued downstream advisories (Red Hat Bugzilla).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management