CVE-2026-5904
vulnerability analysis and mitigation

Overview

CVE-2026-5904 is a use-after-free vulnerability in the V8 JavaScript engine within Google Chrome and Microsoft Edge (Chromium-based). It was reported by Zhenpeng (Leo) Lin at depthfirst on 2026-02-12 and publicly disclosed on April 7–8, 2026, as part of the Chrome 147 stable channel release. The vulnerability affects Google Chrome versions prior to 147.0.7727.55 and corresponding Microsoft Edge Chromium builds. Google assigned it a Chromium security severity of Low, though the NVD CVSS v3.1 base score is 8.8 (High) (Chrome Release, GitHub Advisory).

Technical details

The vulnerability is classified as CWE-416 (Use After Free) and resides in Chrome's V8 JavaScript engine. According to the official description, an attacker who convinces a user to install a malicious Chrome extension can trigger the use-after-free condition, potentially leading to heap corruption via a crafted extension (GitHub Advisory, Chrome Release). Exploitation requires user interaction — specifically, the victim must install a malicious browser extension — making the attack vector network-based but dependent on social engineering. The Chromium issue tracker entry is referenced as issue #483851888, though full bug details remain restricted pending broad user adoption of the patch.

Impact

Successful exploitation could allow an attacker to achieve heap corruption in the V8 engine, potentially leading to arbitrary code execution within the browser's renderer process, memory corruption, or browser crash. The CVSS assessment rates confidentiality, integrity, and availability impacts all as High, meaning a fully weaponized exploit could result in data theft, unauthorized code execution, or denial of service within the browser context (GitHub Advisory). However, the practical impact is constrained by the requirement for user interaction (installing a malicious extension) and Chrome's sandbox architecture, which limits lateral movement to the host system without a sandbox escape.

Mitigation and workarounds

Google has released a patch in Chrome 147.0.7727.55 (Linux) and 147.0.7727.55/56 (Windows/Mac), which addresses this vulnerability along with numerous other security fixes (Chrome Release). Microsoft has released a corresponding update for Edge Chromium (Microsoft MSRC). Recommended actions include: (1) updating Chrome and Edge to the latest stable versions immediately; (2) enforcing enterprise extension policies to restrict installation of extensions to those from approved sources only; and (3) educating users about the risks of installing extensions from untrusted sources.

Community reactions

The Chrome 147 release was covered by security news outlets including GBHackers, which highlighted the broader set of critical and high-severity flaws patched in the update (GBHackers). The SANS Internet Storm Center also noted the release in its diary (SANS ISC). Community reaction was generally routine given the Low Chromium severity rating assigned to this specific CVE, with more attention directed at the two Critical WebML vulnerabilities (CVE-2026-5858, CVE-2026-5859) patched in the same release.

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management