
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5884 is an insufficient input validation vulnerability in the Media component of Google Chrome that allows a remote attacker who has already compromised the renderer process to execute arbitrary code inside the sandbox via a crafted HTML page. It affects Google Chrome versions prior to 147.0.7727.55 on Windows, Mac, and Linux, as well as Microsoft Edge (Chromium-based). The vulnerability was reported by researcher xmzyshypnc on February 15, 2026, and publicly disclosed on April 8, 2026, when Google released Chrome 147.0.7727.55. It carries a CVSS v3.1 base score of 8.8 (High) and is rated Medium severity by Chromium's internal severity scale (Chrome Releases, GitHub Advisory).
The vulnerability is classified as CWE-20 (Improper Input Validation) and resides in Chrome's Media component (Chromium issue #484547633). Insufficient validation of untrusted input within the Media subsystem allows an attacker who has already gained control of the renderer process to supply maliciously crafted input via a specially constructed HTML page, triggering arbitrary code execution within the renderer sandbox. Exploitation requires prior compromise of the renderer process (e.g., through a separate vulnerability) and user interaction — specifically, a victim visiting a crafted web page — making this a post-compromise, sandbox-escape-class issue rather than a standalone remote code execution flaw (Chrome Releases, GitHub Advisory).
Successful exploitation allows an attacker who has already compromised the Chrome renderer process to execute arbitrary code within the renderer sandbox, achieving high confidentiality, integrity, and availability impact on the affected browser instance. While the impact is contained within the sandbox environment and does not directly represent a full system compromise, it can serve as a stepping stone in a multi-stage attack chain — for example, chained with a sandbox escape vulnerability to achieve full host-level code execution. Sensitive data accessible within the browser context (cookies, credentials, browsing history) could be exposed (GitHub Advisory, Feedly).
Google has released a patch in Chrome 147.0.7727.55 (Linux) and 147.0.7727.55/56 (Windows/Mac), which addresses this vulnerability. Microsoft has also released a corresponding security update for Edge (Chromium-based). Users should update Google Chrome to version 147.0.7727.55 or later immediately via the browser's built-in update mechanism (Settings → Help → About Google Chrome). No configuration-based workaround is available; upgrading is the only remediation. Additionally, maintaining general browser hygiene — avoiding untrusted websites and keeping the OS patched — reduces the risk of the renderer compromise that is a prerequisite for this vulnerability (Chrome Releases, Microsoft MSRC).
The Chrome 147 release was covered by security news outlets including GBHackers, which highlighted the update as patching 60 vulnerabilities including two critical WebML flaws. Linux distribution security teams (Debian, openSUSE, Fedora, FreeBSD) issued their own advisories and package updates for Chromium. Palo Alto Networks also released an advisory (PAN-SA-2026-0007) referencing this CVE in the context of their Chromium-based products. Community reaction was generally routine given the medium Chromium severity rating and the post-compromise exploitation prerequisite (Chrome Releases).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."