
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5886 is an out-of-bounds read vulnerability in the WebAudio component of Google Chrome on macOS that allows a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. It was reported by researcher c6eed09fc8b174b0f3eebedcceb1e792 on February 18, 2026, and publicly disclosed on April 8, 2026, as part of the Chrome 147 stable channel release. The vulnerability affects Google Chrome versions prior to 147.0.7727.55 on Mac, and Microsoft Edge (Chromium-based) is also listed as an affected product. It carries a CVSS v3.1 base score of 5.3 (Medium) per NVD/Feedly, though the GitHub Advisory Database assigns a higher score of 7.5 (High) under a different scoring interpretation. Chromium's internal severity rating is Medium (Chrome Releases, GitHub Advisory).
The vulnerability is classified as CWE-125 (Out-of-bounds Read) and resides in Chrome's WebAudio subsystem, specifically on macOS. When processing a specially crafted HTML page, the WebAudio component attempts to read memory outside its allocated buffer bounds, potentially exposing contents of the Chrome renderer process memory to the attacker. Exploitation requires user interaction — a victim must visit a malicious or attacker-controlled web page — and the attack complexity is rated High under the NVD scoring, reflecting that specific conditions must be met for successful exploitation. The Chromium bug tracker references issue #485397283, though full technical details remain restricted pending broad user patching (Chrome Releases, GitHub Advisory).
Successful exploitation allows a remote attacker to read potentially sensitive data from Chrome's process memory, impacting confidentiality. This could expose in-memory secrets such as authentication tokens, session cookies, or other data processed by the browser at the time of exploitation. There is no integrity or availability impact — the vulnerability is limited to information disclosure within the scope of the Chrome renderer process on macOS (Chrome Releases, GitHub Advisory).
Google Chrome Helper (Renderer)) on macOS.Google has released Chrome 147.0.7727.55 (Linux) and 147.0.7727.55/56 (Windows/Mac) which contains the fix for CVE-2026-5886. Organizations should immediately update all macOS Chrome installations to version 147.0.7727.55 or later. Microsoft has also issued guidance for Edge (Chromium-based) users via the MSRC advisory. Enterprise administrators should enforce automatic browser update policies to ensure timely patching across managed endpoints (Chrome Releases, Microsoft MSRC).
The Chrome 147 update was covered by security news outlets including GBHackers, which highlighted the broader set of critical and high-severity flaws patched in the release. The SANS Internet Storm Center (ISC) also noted the update in their diary. Downstream Linux distributions including Debian and openSUSE issued their own Chromium security advisories. Palo Alto Networks published a security advisory (PAN-SA-2026-0007) referencing this and related CVEs for their products that embed Chromium. Community reaction was generally routine given the Medium severity rating and absence of active exploitation (Chrome Releases).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."