
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5914 is a Type Confusion vulnerability in the CSS processing component of Google Chrome that allows an attacker who convinces a user to install a malicious extension to potentially exploit heap corruption. It affects all Google Chrome versions prior to 147.0.7727.55 on Windows, Mac, and Linux. The vulnerability was reported by researcher Syn4pse on 2026-03-05 and publicly disclosed on 2026-04-08 as part of the Chrome 147 stable channel release. It carries a CVSS v3.1 base score of 8.8 (High), though Google internally rates its Chromium security severity as Low (Chrome Releases, GitHub Advisory).
The vulnerability is classified as CWE-843 (Access of Resource Using Incompatible Type / 'Type Confusion'), occurring within Chrome's CSS processing subsystem. When a malicious Chrome Extension crafted to trigger the type confusion is installed, it can cause heap corruption by accessing a CSS-related resource using an incompatible type from the one it was originally allocated with. Exploitation requires user interaction — specifically, the victim must be convinced to install a malicious extension — making the attack vector network-based but dependent on social engineering. The Chromium bug tracker references issue #490023239, though full technical details remain restricted pending broad user adoption of the patch (Chrome Releases, GitHub Advisory).
Successful exploitation could lead to heap corruption within the Chrome browser process, potentially enabling arbitrary code execution with the privileges of the Chrome renderer or browser process. This could result in unauthorized access to sensitive data processed by the browser (credentials, session tokens, browsing history), system compromise, or installation of additional malware. The confidentiality, integrity, and availability impacts are all rated High per the CVSS scoring, though the practical exploitability is constrained by the requirement for the victim to install a malicious extension (GitHub Advisory, Chrome Releases).
chrome://extensions/ with broad permissions (e.g., access to all URLs, tabs, or storage); extension files located in unexpected directories outside the standard Chrome profile extension folder.cmd.exe, powershell.exe, bash, curl, wget) that are not typical browser subprocesses.Users and organizations should immediately update Google Chrome to version 147.0.7727.55 or later, which contains the fix for this vulnerability (Chrome Releases). Microsoft Edge (Chromium-based) users should also apply the corresponding Edge update. As a workaround, enterprise administrators can enforce Chrome extension policies via Group Policy or Chrome Enterprise to restrict extension installations to an approved allowlist, preventing users from installing arbitrary extensions. Users should be educated not to install Chrome extensions from untrusted or unofficial sources.
The Chrome 147 update was covered by security news outlets including GBHackers, which highlighted the broader release containing 60+ vulnerability fixes including two critical WebML flaws (GBHackers). The SANS Internet Storm Center also noted the release (SANS ISC). CVE-2026-5914 itself, rated Low severity by Google internally, received limited individual attention given its social-engineering prerequisite and low EPSS score. Downstream Linux distributions including Debian and openSUSE issued their own advisories for the Chromium package update.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."