
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5904 is a use-after-free vulnerability in the V8 JavaScript engine within Google Chrome and Microsoft Edge (Chromium-based). It was reported by Zhenpeng (Leo) Lin at depthfirst on 2026-02-12 and publicly disclosed on April 7–8, 2026, as part of the Chrome 147 stable channel release. The vulnerability affects Google Chrome versions prior to 147.0.7727.55 and corresponding Microsoft Edge Chromium builds. Google assigned it a Chromium security severity of Low, though the NVD CVSS v3.1 base score is 8.8 (High) (Chrome Release, GitHub Advisory).
The vulnerability is classified as CWE-416 (Use After Free) and resides in Chrome's V8 JavaScript engine. According to the official description, an attacker who convinces a user to install a malicious Chrome extension can trigger the use-after-free condition, potentially leading to heap corruption via a crafted extension (GitHub Advisory, Chrome Release). Exploitation requires user interaction — specifically, the victim must install a malicious browser extension — making the attack vector network-based but dependent on social engineering. The Chromium issue tracker entry is referenced as issue #483851888, though full bug details remain restricted pending broad user adoption of the patch.
Successful exploitation could allow an attacker to achieve heap corruption in the V8 engine, potentially leading to arbitrary code execution within the browser's renderer process, memory corruption, or browser crash. The CVSS assessment rates confidentiality, integrity, and availability impacts all as High, meaning a fully weaponized exploit could result in data theft, unauthorized code execution, or denial of service within the browser context (GitHub Advisory). However, the practical impact is constrained by the requirement for user interaction (installing a malicious extension) and Chrome's sandbox architecture, which limits lateral movement to the host system without a sandbox escape.
Google has released a patch in Chrome 147.0.7727.55 (Linux) and 147.0.7727.55/56 (Windows/Mac), which addresses this vulnerability along with numerous other security fixes (Chrome Release). Microsoft has released a corresponding update for Edge Chromium (Microsoft MSRC). Recommended actions include: (1) updating Chrome and Edge to the latest stable versions immediately; (2) enforcing enterprise extension policies to restrict installation of extensions to those from approved sources only; and (3) educating users about the risks of installing extensions from untrusted sources.
The Chrome 147 release was covered by security news outlets including GBHackers, which highlighted the broader set of critical and high-severity flaws patched in the update (GBHackers). The SANS Internet Storm Center also noted the release in its diary (SANS ISC). Community reaction was generally routine given the Low Chromium severity rating assigned to this specific CVE, with more attention directed at the two Critical WebML vulnerabilities (CVE-2026-5858, CVE-2026-5859) patched in the same release.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."