
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5879 is an insufficient input validation vulnerability in the ANGLE graphics library within Google Chrome on Mac, allowing a remote attacker to execute arbitrary code inside the browser sandbox via a crafted HTML page. The vulnerability was originally reported by parkminchan of SSD Labs Korea on 2023-10-01 and publicly disclosed on April 8, 2026, as part of the Chrome 147 stable channel release. It affects Google Chrome versions prior to 147.0.7727.55 on Mac, as well as Microsoft Edge (Chromium-based). It carries a CVSS v3.1 base score of 8.8 (High) (Chrome Releases, GitHub Advisory).
The root cause is classified as CWE-20 (Improper Input Validation) in ANGLE (Almost Native Graphics Layer Engine), Chrome's cross-platform OpenGL ES implementation used for rendering graphics. The flaw arises from insufficient validation of untrusted input processed by ANGLE on macOS, which can be triggered when a user visits a specially crafted HTML page. Exploitation requires user interaction (visiting a malicious page) but no special privileges, and the attack is delivered over the network. The Chromium issue tracker references bug ID 40073848, though full technical details remain restricted pending broad user adoption of the patch (Chrome Releases, GitHub Advisory).
Successful exploitation allows a remote attacker to execute arbitrary code within the Chrome browser sandbox on macOS without requiring any privileges, achieved solely through user interaction with a malicious web page. The impact spans high confidentiality, integrity, and availability — an attacker could access sensitive browser data, modify browser state, or cause denial of service within the sandboxed process. While the sandbox limits direct host OS compromise, sandbox escape chained with this vulnerability could lead to broader system compromise (GitHub Advisory, Feedly).
Google has released Chrome 147.0.7727.55 (Linux) and 147.0.7727.55/56 (Windows/Mac) which addresses this vulnerability. Users should update Google Chrome to version 147.0.7727.55 or later immediately, particularly on macOS systems. Microsoft Edge (Chromium-based) users should also apply the corresponding updated version. As a temporary workaround prior to patching, users should avoid visiting untrusted or suspicious websites, and organizations may consider implementing browser security policies to restrict potentially malicious web content (Chrome Releases, Microsoft Advisory).
The vulnerability was covered by GBHackers as part of broader reporting on Chrome 147's security fixes, which addressed over 60 vulnerabilities including two critical WebML flaws. The SANS Internet Storm Center (ISC) also noted the Chrome 147 update in their diary. Community and vendor reactions have been routine given the medium Chromium severity rating and absence of active exploitation, with no exceptional researcher commentary or significant social media discussion identified beyond standard patch notification channels (Chrome Releases).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."