
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5888 is an "Uninitialized Use in WebCodecs" vulnerability in Google Chrome that allows a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. It affects all versions of Google Chrome prior to 147.0.7727.55 on Windows, Mac, and Linux, as well as Microsoft Edge (Chromium-based). The vulnerability was reported by the Octane Security Team (Giovanni Vignone, Paolo Gentry, Robert van Eijk) on 2026-02-22 and publicly disclosed on 2026-04-08 alongside the Chrome 147 stable channel release. It carries a CVSS v3.1 base score of 6.5 (Medium) (Chrome Releases, GitHub Advisory).
The vulnerability is classified as CWE-457 (Use of Uninitialized Variable) and resides in Chrome's WebCodecs component, which provides low-level access to audio and video codec functionality within the browser. When processing certain media-related operations, the WebCodecs implementation fails to properly initialize variables before use, leaving memory regions that may contain residual data from prior operations accessible to attacker-controlled logic. Exploitation requires the victim to visit a specially crafted HTML page, which can trigger the uninitialized memory read via WebCodecs API calls, potentially leaking contents of the Chrome renderer process memory. The Chromium issue tracker entry for this bug is tracked as issue #486506202 (Chrome Releases, GitHub Advisory).
Successful exploitation results in an information disclosure impact, with high confidentiality impact and no effect on integrity or availability. A remote attacker who tricks a user into visiting a malicious webpage could read sensitive data from the Chrome renderer process memory, potentially exposing encryption keys, authentication tokens, user credentials, or other confidential data previously processed by the browser. The scope is limited to the Chrome renderer process and does not directly enable code execution or privilege escalation, though leaked memory contents could facilitate further attacks (GitHub Advisory, Feedly).
VideoDecoder, AudioDecoder, or related interfaces) in a sequence that triggers the use of an uninitialized variable within the WebCodecs component.VideoDecoder, AudioDecoder, VideoEncoder) on endpoints that do not normally use media codec functionality.The primary remediation is to upgrade Google Chrome to version 147.0.7727.55 or later (147.0.7727.55 for Linux; 147.0.7727.55/56 for Windows and Mac), which contains the fix for this vulnerability (Chrome Releases). Microsoft Edge users should apply the corresponding Chromium-based Edge update via the Microsoft Security Response Center (Microsoft MSRC). Organizations should enforce automatic browser updates to ensure timely patching across all endpoints. No configuration-based workaround is available; patching is the only effective mitigation.
The vulnerability was covered by security news outlets including GBHackers, which reported on the broader Chrome 147 update that patched 60 vulnerabilities including this one (GBHackers). The SANS Internet Storm Center also noted the Chrome 147 release in its diary (SANS ISC). Community and industry reaction was measured given the Medium severity rating and absence of active exploitation; the patch was noted as part of a large batch release rather than an emergency out-of-band update.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."