
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5877 is a use-after-free vulnerability in the Navigation component of Google Chrome that allows a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. It affects Google Chrome versions prior to 147.0.7727.55 and Microsoft Edge (Chromium-based). The vulnerability was originally reported by Cassidy Kim (@cassidy6564) on April 5, 2024, and was publicly disclosed on April 8, 2026, as part of the Chrome 147 stable channel release. It carries a CVSS v3.1 base score of 8.8 (High) and is rated Medium severity by Chromium's internal security team (Chrome Releases, GitHub Advisory).
The vulnerability is classified as CWE-416 (Use After Free), occurring in Chrome's Navigation component. A use-after-free condition arises when memory that has been freed is subsequently referenced or reused, potentially allowing an attacker to control program execution by manipulating heap memory layout. Exploitation requires a victim to visit or be directed to a specially crafted HTML page, after which the attacker can trigger the memory corruption to achieve arbitrary code execution within the browser's sandbox. The Chromium issue tracker references bug ID 333024273, though full technical details remain restricted pending widespread user patching (Chrome Releases, GitHub Advisory).
Successful exploitation allows a remote attacker to execute arbitrary code within the Chrome renderer sandbox, with high impact to confidentiality, integrity, and availability of the affected browser process. While the sandbox limits direct access to the underlying operating system, code execution within the sandbox can serve as a stepping stone for sandbox escape chains, enabling potential data theft, credential harvesting, or further system compromise. User interaction is required — the victim must visit a malicious webpage — limiting mass exploitation but not targeted attacks (GitHub Advisory, Feedly).
chrome.exe or msedge.exe (e.g., cmd.exe, powershell.exe, bash) that are not typical browser helper processes; renderer process crashes or abnormal termination logs.chrome://crashes) showing repeated renderer crashes tied to specific URLs.Google has released Chrome 147.0.7727.55 (Linux) and 147.0.7727.55/56 (Windows/Mac) which addresses this vulnerability. Microsoft has released a corresponding security update for Edge (Chromium-based). Users and organizations should update Chrome and Edge to the latest available versions immediately and ensure automatic browser updates are enabled. No configuration-based workaround is available; patching is the only effective remediation (Chrome Releases, Microsoft MSRC).
The Chrome 147 release was covered by security news outlets including GBHackers, which highlighted the batch of critical and high-severity flaws patched in the update. Linux distribution security teams (Debian, openSUSE, Fedora) issued downstream advisories and package updates for Chromium. The SANS Internet Storm Center also noted the release in their diary. No significant controversy or notable researcher commentary specific to CVE-2026-5877 has been observed, as the vulnerability is rated Medium by Chromium's internal team despite its High CVSS score (GBHackers, SANS ISC).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."