
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5910 is an integer overflow vulnerability in the Media component of Google Chrome that allows a remote attacker to potentially exploit heap corruption via a crafted video file. It affects all versions of Google Chrome prior to 147.0.7727.55 on Windows, Mac, and Linux. The vulnerability was reported by Ameen Basha M K and Mohammed Yasar B on February 17, 2026, and publicly disclosed on April 8, 2026, when Google released Chrome 147. It carries a CVSS v3.1 base score of 8.8 (High), though Google internally rated it as Low severity (Chrome Release, GitHub Advisory).
The root cause is an integer overflow (CWE-472 is listed, though the core issue is an integer overflow in media processing code) in Chrome's Media component when handling video file data. When a specially crafted video file is processed, arithmetic operations on media metadata or buffer size calculations can overflow, resulting in heap memory corruption. Exploitation requires user interaction — specifically, a victim must open or view a malicious video file delivered via a web page or other mechanism. The Chromium bug tracker references issue #485212874 for this vulnerability, though full technical details remain restricted pending broad user patching (Chrome Release, GitHub Advisory).
Successful exploitation could allow a remote attacker to achieve arbitrary code execution with the privileges of the Chrome browser process, or cause application crashes affecting availability. The heap corruption resulting from the integer overflow can be leveraged to manipulate memory layout, potentially enabling full confidentiality, integrity, and availability compromise of the browser process. While Chrome's sandbox mitigates the risk of full system compromise, a successful exploit could still expose sensitive browser data (cookies, credentials, session tokens) and serve as a stepping stone for sandbox escape in chained attack scenarios (GitHub Advisory, Feedly).
<video> tag or similar media element.cmd.exe, powershell.exe, /bin/sh) or making unusual system calls after processing video content.libmedia, ffmpeg-related components); repeated Chrome crash events tied to specific video URLs.Google has released Chrome 147.0.7727.55 (Linux) and 147.0.7727.55/56 (Windows/Mac) which addresses this vulnerability. Organizations should ensure Chrome is updated to version 147.0.7727.55 or later across all endpoints. Microsoft Edge (Chromium-based) users should also apply the corresponding Edge update. No configuration-based workaround is available; updating to the patched version is the only remediation. Administrators can use enterprise management tools (e.g., Google Admin Console, Microsoft Intune) to verify and enforce deployment of the patched version (Chrome Release, Microsoft MSRC).
The Chrome 147 release was covered by security news outlets including GBHackers, which noted the update patched 60 vulnerabilities including two critical WebML flaws alongside this lower-severity issue (GBHackers). The SANS Internet Storm Center also logged the release (SANS ISC). Community reaction has been muted given the Low internal severity rating assigned by Google and the absence of active exploitation or public PoC code.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."