
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5885 is an insufficient input validation vulnerability in the WebML component of Google Chrome on Windows that allows a remote attacker to read potentially sensitive information from process memory via a crafted HTML page. It was reported by Bryan Bernhart on February 17, 2026 (Chromium issue #485203823) and publicly disclosed on April 8, 2026 as part of the Chrome 147 stable channel release. The vulnerability affects all Google Chrome versions prior to 147.0.7727.55 on Windows, and Microsoft Edge (Chromium-based) is also listed as an affected product. It carries a CVSS v3.1 base score of 6.5 (Medium) (Chrome Releases, GitHub Advisory).
The root cause is classified as CWE-20 (Improper Input Validation): Chrome's WebML subsystem — which exposes machine learning inference capabilities to web content — fails to adequately validate untrusted input supplied via a crafted HTML page (GitHub Advisory). This allows attacker-controlled data to be processed without proper bounds or type checks, resulting in an out-of-bounds or uninitialized memory read that leaks contents of the Chrome renderer process memory. Exploitation requires the victim to visit a malicious webpage (user interaction required), but no authentication or elevated privileges are needed on the attacker's side. The attack vector is network-based with low complexity, making it straightforward to trigger once a target visits the attacker-controlled page (Chrome Releases).
Successful exploitation results in a high-confidentiality-impact information disclosure: an attacker can extract potentially sensitive data from the Chrome renderer process memory, which may include cached credentials, session tokens, personal data, or other in-memory content from the browsing session. Integrity and availability are not affected by this vulnerability. While the scope is limited to the renderer process (sandbox boundary), leaked memory contents could facilitate further attacks or credential theft (GitHub Advisory, Chrome Releases).
navigator.ml) with specially crafted, malformed input tensors or model parameters that bypass input validation in Chrome's WebML implementation.navigator.ml); unusual data exfiltration patterns (e.g., large POST requests) following page visits.chrome.exe renderer subprocess) coinciding with visits to unknown sites; security tool alerts on out-of-bounds memory access in the Chrome renderer sandbox.The primary remediation is to update Google Chrome to version 147.0.7727.55 or later, which was released on April 7, 2026 and addresses this vulnerability (Chrome Releases). Microsoft Edge (Chromium-based) users should also apply the corresponding Edge update (Microsoft MSRC). No configuration-based workaround is publicly documented; upgrading is the recommended and only confirmed fix. Organizations should prioritize patching all Windows endpoints running Chrome, as exploitation requires only a webpage visit.
The Chrome 147 release was covered by security news outlets including GBHackers, which highlighted the batch of 60+ vulnerabilities patched in the update, including multiple WebML flaws (GBHackers). BeyondMachines noted the two critical WebML CVEs (CVE-2026-5858 and CVE-2026-5859) as the headline items, with CVE-2026-5885 receiving less individual attention given its Medium severity rating. The SANS Internet Storm Center also logged the update (SANS ISC). No significant researcher commentary or social media discussion specific to CVE-2026-5885 has been observed beyond standard vulnerability tracking.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."