
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5913 is an out-of-bounds read vulnerability in the Blink rendering engine of Google Chrome that allows a remote attacker to perform an out-of-bounds memory read via a crafted HTML page. It was reported by Vitaly Simonovich on February 24, 2026, and publicly disclosed on April 7–8, 2026, as part of the Chrome 147 stable channel release. The vulnerability affects Google Chrome versions prior to 147.0.7727.55 on Windows, Mac, and Linux, as well as Microsoft Edge (Chromium-based). It carries a CVSS v3.1 base score of 8.1 (High), though Google internally rated it as Low severity (Chrome Release, GitHub Advisory).
The vulnerability is classified as CWE-125 (Out-of-bounds Read) and resides in Blink, Chrome's HTML rendering engine. An attacker can exploit this flaw by crafting a malicious HTML page that, when rendered by the browser, causes Blink to read memory beyond the bounds of an allocated buffer. Exploitation requires user interaction — specifically, a victim must visit the attacker-controlled page — but requires no special privileges or authentication. The Chromium issue tracker references bug ID 487195286 for this vulnerability (Chrome Release, GitHub Advisory).
Successful exploitation could allow a remote attacker to read sensitive data from process memory, potentially exposing credentials, session tokens, or other confidential information processed by the browser. The CVSS scoring reflects high confidentiality and availability impact, meaning the vulnerability could also contribute to browser instability or crashes. Because the attack is delivered via a web page, any user running an unpatched version of Chrome or Edge who visits a malicious site is at risk, with no lateral movement capability beyond the browser process itself (GitHub Advisory, Chrome Release).
Google has addressed this vulnerability in Chrome 147.0.7727.55 (Linux) and 147.0.7727.55/56 (Windows/Mac), released on April 7, 2026. Microsoft has also issued corresponding patches for Edge (Chromium-based). Users should update Chrome or Edge to the latest available version immediately, and ensure automatic browser updates are enabled. No configuration-based workaround is available; patching is the only remediation (Chrome Release, Microsoft MSRC).
Coverage of CVE-2026-5913 was largely aggregated alongside the broader Chrome 147 security release, which included over 60 vulnerabilities including two Critical-rated WebML flaws. Security news outlets such as GBHackers covered the Chrome 147 update as a whole, noting the scale of the patch batch. No specific researcher commentary or notable social media discussion focused exclusively on CVE-2026-5913, consistent with its Low internal severity rating from Google (Chrome Release).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."