
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5883 is a use-after-free vulnerability in the Media component of Google Chrome that allows a remote attacker to execute arbitrary code inside the browser sandbox via a crafted HTML page. It was reported by researcher "sherkito" on February 9, 2026 (Chromium issue #482958590), and patched on April 1, 2026 with the release of Chrome 147.0.7727.55. All versions of Google Chrome prior to 147.0.7727.55 are affected; Microsoft Edge (Chromium-based) is also impacted. The vulnerability carries a CVSS v3.1 base score of 8.8 (High) and is rated Medium severity by Chromium's internal severity scale (Chrome Release, GitHub Advisory).
The vulnerability is classified as CWE-416 (Use After Free), occurring in Chrome's Media component. A use-after-free condition arises when memory associated with a media object is freed but a dangling pointer to that memory is subsequently accessed, allowing an attacker to control or corrupt heap memory. Exploitation requires a victim to visit a specially crafted HTML page, which triggers the vulnerable code path in the Media subsystem. The attack vector is network-based with low complexity and no privileges required, though user interaction (visiting a malicious page) is necessary (Chrome Release, GitHub Advisory). Bug details remain restricted in the Chromium issue tracker (issue #482958590) pending broad user adoption of the fix.
Successful exploitation allows a remote attacker to execute arbitrary code within the Chrome sandbox environment, resulting in high confidentiality, integrity, and availability impact on the affected browser process. An attacker could read sensitive data accessible to the browser, modify browser state or data, or crash the browser entirely. While the sandbox limits direct host OS compromise, this vulnerability could serve as a stepping stone in a sandbox escape chain if combined with additional exploits (GitHub Advisory, Chrome Release).
Google has released Chrome 147.0.7727.55 (Linux) and 147.0.7727.55/56 (Windows/Mac) to address this vulnerability; users should update immediately (Chrome Release). Microsoft Edge (Chromium-based) users should apply the corresponding patched Edge version available through the Microsoft Security Response Center (Microsoft MSRC). Enabling automatic browser updates is strongly recommended to ensure timely patching. As an interim measure, users should avoid visiting untrusted or suspicious websites, and organizations should consider deploying web filtering or browser isolation solutions for high-risk environments.
The Chrome 147 update was covered by security news outlets including GBHackers, which highlighted the release as patching 60 vulnerabilities including critical WebML flaws alongside this medium-severity issue. Linux distribution security teams (Debian, openSUSE, Fedora) issued downstream advisories and package updates for Chromium. The SANS Internet Storm Center also noted the release in a diary entry. No significant controversy or notable researcher commentary specific to CVE-2026-5883 has been observed beyond standard patch reporting.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."