CVE-2026-5912
vulnerability analysis and mitigation

Overview

CVE-2026-5912 is an integer overflow vulnerability in the WebRTC component of Google Chrome that allows a remote attacker to perform an out-of-bounds memory write via a crafted HTML page. The vulnerability was reported by researcher c6eed09fc8b174b0f3eebedcceb1e792 on 2026-02-22 and publicly disclosed on 2026-04-01 as part of the Chrome 147 stable channel release. It affects all versions of Google Chrome prior to 147.0.7727.55, and Microsoft Edge (Chromium-based) is also listed as an affected product. Google rated this vulnerability as Low severity internally, though it carries a CVSS v3.1 base score of 8.8 (High) (Chrome Release Blog, GitHub Advisory).

Technical details

The root cause is an integer overflow (CWE-472 — External Control of Assumed-Immutable Web Parameter) in Chrome's WebRTC component, which handles real-time communication features such as audio/video streaming. When processing specially crafted WebRTC-related data within a malicious HTML page, an arithmetic integer overflow occurs that causes a subsequent out-of-bounds memory write, potentially corrupting heap memory. Exploitation requires user interaction — specifically, a victim must visit or be redirected to a malicious web page. The Chromium issue tracker entry is referenced as bug #486498791, though full technical details remain restricted pending broad user adoption of the patch (Chrome Release Blog, GitHub Advisory).

Impact

Successful exploitation could allow a remote attacker to perform an out-of-bounds memory write, potentially leading to arbitrary code execution with the privileges of the Chrome browser process. This could enable an attacker to steal sensitive data, modify files on the system, install malware, or use the compromised browser as a pivot point for further lateral movement within a network. Denial of service through memory corruption is also a possible outcome (GitHub Advisory, Feedly).

Mitigation and workarounds

Google has addressed this vulnerability in Chrome 147.0.7727.55 (Linux) and 147.0.7727.55/56 (Windows/Mac), released on April 7, 2026. Users and administrators should update Google Chrome to version 147.0.7727.55 or later immediately on all affected systems (Chrome Release Blog). As a temporary measure prior to patching, users should avoid visiting untrusted or suspicious websites, and organizations should consider enabling automatic browser updates and enforcing browser security policies. Microsoft Edge (Chromium-based) users should also apply the corresponding Edge update from Microsoft (Microsoft MSRC).

Community reactions

The Chrome 147 release was covered by security news outlets including GBHackers, which highlighted the broader set of critical and high-severity flaws patched in the update (GBHackers). The SANS Internet Storm Center also noted the release in their diary (SANS ISC). Community discussion was observed on Mastodon/VulDB and Bluesky, with general acknowledgment of the patch but no significant alarm given the Low internal severity rating assigned by Google. No notable independent researcher commentary specific to CVE-2026-5912 has been published.

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management