
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5908 is an integer overflow vulnerability in the Media component of Google Chrome that allows a remote attacker to potentially exploit heap corruption via a crafted video file. It affects all versions of Google Chrome prior to 147.0.7727.55 on Windows, Mac, and Linux. The vulnerability was reported by Ameen Basha M K and Mohammed Yasar B on February 17, 2026, and patched with the Chrome 147 stable channel release on April 7, 2026. Google assigned it a Chromium security severity of Low, though it carries a CVSS v3.1 base score of 8.8 (High) (Chrome Releases, GitHub Advisory).
The root cause is an integer overflow (CWE-190) in Chrome's Media component, which can lead to heap corruption when processing a specially crafted video file. The Feedly data also references CWE-472 (External Control of Assumed-Immutable Web Parameter), though the primary mechanism is the integer overflow triggering out-of-bounds memory operations. Exploitation requires user interaction — specifically, a victim must open or load a malicious video file, which can be delivered via a web page or as a file download. The Chromium issue tracker entry is referenced as bug #485115554, though full technical details remain restricted pending broad user update (Chrome Releases, GitHub Advisory).
Successful exploitation could allow a remote attacker to cause heap corruption in the Chrome browser process, potentially leading to arbitrary code execution with the privileges of the browser process. This could result in high confidentiality, integrity, and availability impacts — including unauthorized access to sensitive user data, browser session hijacking, or further system compromise. Because the vulnerability is triggered through media processing, it could be embedded in a malicious web page or delivered as a video file, enabling drive-by style attacks against end users (GitHub Advisory, Feedly).
Google has released Chrome 147.0.7727.55 (Linux) and 147.0.7727.55/56 (Windows/Mac) to address this vulnerability. Users and organizations should update Chrome immediately to version 147.0.7727.55 or later; enabling automatic updates is strongly recommended. As a precautionary measure, users should avoid opening video files from untrusted sources or visiting suspicious websites until the update is applied. Microsoft Edge (Chromium-based) users should also apply the corresponding Edge update (Chrome Releases, Microsoft MSRC).
The Chrome 147 update was covered by security news outlets including GBHackers, which highlighted the broader batch of 60+ vulnerabilities patched in this release, including two critical WebML flaws alongside this lower-severity Media integer overflow. The SANS Internet Storm Center also noted the update in its diary. No significant independent researcher commentary or social media discussion specific to CVE-2026-5908 has been identified, consistent with its Low Chromium severity rating and lack of known exploitation (GBHackers, SANS ISC).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."