
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5902 is a race condition vulnerability in the Media component of Google Chrome on Android, classified with Chromium security severity: Low. It was reported by Luke Francis on 2026-02-10 and publicly disclosed on April 8, 2026, as part of the Chrome 147 stable channel release. The vulnerability affects Google Chrome versions prior to 147.0.7727.55, as well as Microsoft Edge (Chromium-based) versions based on the same codebase. Despite its Low Chromium severity rating, the NVD assigned a CVSS v3.1 base score of 9.8 (Critical), reflecting the theoretical worst-case impact (Chrome Releases, GitHub Advisory).
The vulnerability is classified as CWE-362 (Concurrent Execution using Shared Resource with Improper Synchronization / Race Condition). Specifically, a timing window exists in Chrome's Media component on Android where a shared media resource can be modified by a concurrent code sequence, allowing corruption of media stream metadata. Exploitation requires that the attacker has already compromised the renderer process; a crafted HTML page is then used to trigger the race condition. The Chromium bug tracker reference is issue #483109205 (Chrome Releases, GitHub Advisory).
A remote attacker who has already compromised the renderer process can exploit this race condition to corrupt media stream metadata via a crafted HTML page. The practical impact is limited to denial of service or unexpected media behavior within the browser context, as the attacker must first achieve renderer compromise before leveraging this flaw. The NVD's Critical CVSS score reflects a theoretical maximum impact, but the actual exploitability is constrained by the prerequisite of renderer process compromise (GitHub Advisory, Chrome Releases).
Google has released Chrome 147.0.7727.55 (Linux) and 147.0.7727.55/56 (Windows/Mac) which address this vulnerability. Microsoft has also released corresponding security updates for Edge (Chromium-based). Users and administrators should update Google Chrome and Microsoft Edge to the latest available versions immediately. No configuration-based workarounds have been published; updating to the patched version is the only recommended remediation (Chrome Releases, Microsoft MSRC).
The Chrome 147 update was covered by security news outlets including GBHackers, which highlighted the broader set of critical Chrome flaws patched in this release. The update was also noted by Linux security advisories (Debian, openSUSE, Fedora) and the SANS Internet Storm Center diary. Community reaction focused primarily on the two Critical-rated WebML vulnerabilities (CVE-2026-5858, CVE-2026-5859) in the same release, with CVE-2026-5902 receiving less attention due to its Low Chromium severity rating and prerequisite for renderer compromise.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."