CVE-2026-5883
vulnerability analysis and mitigation

Overview

CVE-2026-5883 is a use-after-free vulnerability in the Media component of Google Chrome that allows a remote attacker to execute arbitrary code inside the browser sandbox via a crafted HTML page. It was reported by researcher "sherkito" on February 9, 2026 (Chromium issue #482958590), and patched on April 1, 2026 with the release of Chrome 147.0.7727.55. All versions of Google Chrome prior to 147.0.7727.55 are affected; Microsoft Edge (Chromium-based) is also impacted. The vulnerability carries a CVSS v3.1 base score of 8.8 (High) and is rated Medium severity by Chromium's internal severity scale (Chrome Release, GitHub Advisory).

Technical details

The vulnerability is classified as CWE-416 (Use After Free), occurring in Chrome's Media component. A use-after-free condition arises when memory associated with a media object is freed but a dangling pointer to that memory is subsequently accessed, allowing an attacker to control or corrupt heap memory. Exploitation requires a victim to visit a specially crafted HTML page, which triggers the vulnerable code path in the Media subsystem. The attack vector is network-based with low complexity and no privileges required, though user interaction (visiting a malicious page) is necessary (Chrome Release, GitHub Advisory). Bug details remain restricted in the Chromium issue tracker (issue #482958590) pending broad user adoption of the fix.

Impact

Successful exploitation allows a remote attacker to execute arbitrary code within the Chrome sandbox environment, resulting in high confidentiality, integrity, and availability impact on the affected browser process. An attacker could read sensitive data accessible to the browser, modify browser state or data, or crash the browser entirely. While the sandbox limits direct host OS compromise, this vulnerability could serve as a stepping stone in a sandbox escape chain if combined with additional exploits (GitHub Advisory, Chrome Release).

Mitigation and workarounds

Google has released Chrome 147.0.7727.55 (Linux) and 147.0.7727.55/56 (Windows/Mac) to address this vulnerability; users should update immediately (Chrome Release). Microsoft Edge (Chromium-based) users should apply the corresponding patched Edge version available through the Microsoft Security Response Center (Microsoft MSRC). Enabling automatic browser updates is strongly recommended to ensure timely patching. As an interim measure, users should avoid visiting untrusted or suspicious websites, and organizations should consider deploying web filtering or browser isolation solutions for high-risk environments.

Community reactions

The Chrome 147 update was covered by security news outlets including GBHackers, which highlighted the release as patching 60 vulnerabilities including critical WebML flaws alongside this medium-severity issue. Linux distribution security teams (Debian, openSUSE, Fedora) issued downstream advisories and package updates for Chromium. The SANS Internet Storm Center also noted the release in a diary entry. No significant controversy or notable researcher commentary specific to CVE-2026-5883 has been observed beyond standard patch reporting.

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management