
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5893 is a race condition vulnerability in the V8 JavaScript engine of Google Chrome that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. It was reported by researcher QYmag1c on February 26, 2026, and publicly disclosed on April 8, 2026, as part of the Chrome 147 stable channel release. All Google Chrome versions prior to 147.0.7727.55 are affected, as well as Microsoft Edge (Chromium-based). It carries a CVSS v3.1 base score of 6.8 (Medium), though Chromium's internal severity rating is also Medium (Chrome Releases, GitHub Advisory).
The vulnerability is classified as CWE-362 (Concurrent Execution using Shared Resource with Improper Synchronization / Race Condition) within Chrome's V8 JavaScript engine. A timing window exists in which a shared resource can be modified by a concurrent code sequence, leading to heap corruption. Exploitation requires the victim to visit or be redirected to a specially crafted HTML page, making user interaction a prerequisite. The Chromium issue tracker entry is #487768771, though full technical details remain restricted pending broad user adoption of the patch (Chrome Releases, GitHub Advisory).
Successful exploitation of this race condition could lead to heap corruption in the V8 engine, potentially enabling arbitrary code execution within the Chrome renderer process or causing application crashes. High confidentiality and integrity impacts are assessed (CVSS C:H/I:H), meaning an attacker could access sensitive browser data or tamper with in-memory content, though availability impact is rated None. The attack is network-delivered but requires user interaction (visiting a malicious page), limiting mass exploitation but still posing a meaningful risk to end users on unpatched browsers (GitHub Advisory, Chrome Releases).
Google has addressed this vulnerability in Chrome 147.0.7727.55 (Linux) and 147.0.7727.55/56 (Windows/Mac), released on April 7, 2026. Users should update Chrome immediately via the browser's built-in update mechanism (Settings → Help → About Google Chrome) or enable automatic updates. Microsoft Edge (Chromium-based) users should also apply the corresponding Edge update. As an interim measure, organizations should restrict browsing to untrusted websites and consider deploying web content filtering until patching is complete (Chrome Releases, Microsoft MSRC).
The Chrome 147 release was covered by security-focused outlets including GBHackers, which highlighted the broader set of critical and high-severity flaws patched in this update. Linux distribution security teams (Debian, openSUSE, Fedora) issued downstream advisories for Chromium packages. The SANS Internet Storm Center also noted the release in its diary. No exceptional researcher commentary or social media controversy specific to CVE-2026-5893 has been identified, consistent with its Medium severity rating and lack of active exploitation (GBHackers, Chrome Releases).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."