
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5907 is an out-of-bounds memory read vulnerability in the Media component of Google Chrome, caused by insufficient data validation when processing crafted video files. It was reported by Luke Francis on February 15, 2026, and publicly disclosed on April 7–8, 2026, as part of the Chrome 147 stable channel release. The vulnerability affects all Google Chrome versions prior to 147.0.7727.55 on Windows, Mac, and Linux, as well as Microsoft Edge (Chromium-based). It carries a CVSS v3.1 base score of 8.1 (High), though Google internally rated it Low severity (Chrome Releases, GitHub Advisory).
The root cause is classified as CWE-125 (Out-of-bounds Read): Chrome's Media component fails to adequately validate data boundaries when parsing video file content, allowing a read operation to access memory beyond the intended buffer. An attacker exploits this by delivering a specially crafted video file to a victim — for example, via a malicious web page or a downloaded file — which Chrome's Media subsystem then processes. No elevated privileges are required, but user interaction (opening or navigating to content that triggers video processing) is necessary. The Chromium issue tracker references bug ID 484665123, though full technical details remain restricted pending broad user adoption of the patch (Chrome Releases, GitHub Advisory).
Successful exploitation can result in high confidentiality impact — potentially exposing sensitive data from Chrome's process memory — and high availability impact, which may include application crashes or instability. Because the vulnerability is an out-of-bounds read rather than a write primitive, direct code execution is unlikely without chaining additional vulnerabilities; however, memory disclosure could facilitate information leakage or serve as a stepping stone in a multi-stage attack. The scope is limited to the Chrome renderer process and does not directly affect other system components (GitHub Advisory, Chrome Releases).
chrome.exe / chrome on Linux/Mac) crashing or restarting unexpectedly after loading video content; unusual child process behavior associated with media decoding.The primary remediation is to update Google Chrome to version 147.0.7727.55 or later (147.0.7727.55/56 on Windows/Mac, 147.0.7727.55 on Linux), which contains the fix for this vulnerability (Chrome Releases). Microsoft Edge (Chromium-based) users should also apply the corresponding Edge update. As a temporary workaround prior to patching, organizations should advise users to avoid opening video files from untrusted sources and to be cautious when visiting unfamiliar websites that may auto-play video content. Enterprise administrators should enforce automatic Chrome updates via policy to minimize exposure windows.
The Chrome 147 release was covered by security-focused outlets including GBHackers, which highlighted the broader batch of 60+ vulnerabilities patched in this update, including two critical WebML flaws (GBHackers). BeyondMachines also noted the significance of the Chrome 147 update in the context of the critical WebML vulnerabilities. CVE-2026-5907 itself, rated Low severity by Google internally, received limited individual attention given its lower risk profile relative to the critical and high-severity issues in the same release. No notable researcher commentary specific to this CVE has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."