CVE-2026-5886
vulnerability analysis and mitigation

Overview

CVE-2026-5886 is an out-of-bounds read vulnerability in the WebAudio component of Google Chrome on macOS that allows a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. It was reported by researcher c6eed09fc8b174b0f3eebedcceb1e792 on February 18, 2026, and publicly disclosed on April 8, 2026, as part of the Chrome 147 stable channel release. The vulnerability affects Google Chrome versions prior to 147.0.7727.55 on Mac, and Microsoft Edge (Chromium-based) is also listed as an affected product. It carries a CVSS v3.1 base score of 5.3 (Medium) per NVD/Feedly, though the GitHub Advisory Database assigns a higher score of 7.5 (High) under a different scoring interpretation. Chromium's internal severity rating is Medium (Chrome Releases, GitHub Advisory).

Technical details

The vulnerability is classified as CWE-125 (Out-of-bounds Read) and resides in Chrome's WebAudio subsystem, specifically on macOS. When processing a specially crafted HTML page, the WebAudio component attempts to read memory outside its allocated buffer bounds, potentially exposing contents of the Chrome renderer process memory to the attacker. Exploitation requires user interaction — a victim must visit a malicious or attacker-controlled web page — and the attack complexity is rated High under the NVD scoring, reflecting that specific conditions must be met for successful exploitation. The Chromium bug tracker references issue #485397283, though full technical details remain restricted pending broad user patching (Chrome Releases, GitHub Advisory).

Impact

Successful exploitation allows a remote attacker to read potentially sensitive data from Chrome's process memory, impacting confidentiality. This could expose in-memory secrets such as authentication tokens, session cookies, or other data processed by the browser at the time of exploitation. There is no integrity or availability impact — the vulnerability is limited to information disclosure within the scope of the Chrome renderer process on macOS (Chrome Releases, GitHub Advisory).

Exploitation steps

  1. Craft a malicious HTML page: Develop an HTML page containing JavaScript that invokes the WebAudio API with inputs designed to trigger an out-of-bounds read in the WebAudio component on macOS Chrome.
  2. Host the page: Deploy the malicious page on an attacker-controlled web server accessible to the target.
  3. Lure the victim: Use phishing, malvertising, or a compromised website to direct a macOS Chrome user (running a version prior to 147.0.7727.55) to the malicious page.
  4. Trigger the vulnerability: When the victim's browser loads and processes the page, the WebAudio component reads memory outside its allocated bounds.
  5. Exfiltrate memory contents: The out-of-bounds read result may be observable via JavaScript (e.g., through timing side-channels or direct value leakage), allowing the attacker to infer or extract sensitive data from the Chrome renderer process memory (Chrome Releases, GitHub Advisory).

Indicators of compromise

  • Network: Unexpected outbound connections from macOS systems running Chrome to unfamiliar or newly registered domains shortly after browser activity; HTTP requests to pages with heavy WebAudio API usage from untrusted sources.
  • Logs: Browser crash reports or renderer process termination logs on macOS systems running Chrome versions prior to 147.0.7727.55; Chrome diagnostic logs referencing WebAudio component errors.
  • Process: Unusual child processes or memory access violations associated with the Chrome renderer process (Google Chrome Helper (Renderer)) on macOS.

Mitigation and workarounds

Google has released Chrome 147.0.7727.55 (Linux) and 147.0.7727.55/56 (Windows/Mac) which contains the fix for CVE-2026-5886. Organizations should immediately update all macOS Chrome installations to version 147.0.7727.55 or later. Microsoft has also issued guidance for Edge (Chromium-based) users via the MSRC advisory. Enterprise administrators should enforce automatic browser update policies to ensure timely patching across managed endpoints (Chrome Releases, Microsoft MSRC).

Community reactions

The Chrome 147 update was covered by security news outlets including GBHackers, which highlighted the broader set of critical and high-severity flaws patched in the release. The SANS Internet Storm Center (ISC) also noted the update in their diary. Downstream Linux distributions including Debian and openSUSE issued their own Chromium security advisories. Palo Alto Networks published a security advisory (PAN-SA-2026-0007) referencing this and related CVEs for their products that embed Chromium. Community reaction was generally routine given the Medium severity rating and absence of active exploitation (Chrome Releases).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management