
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5915 is an insufficient input validation vulnerability in the WebML component of Google Chrome that allows a remote attacker to perform an out-of-bounds memory write via a crafted HTML page. It was reported by ningxin.hu@intel.com on 2026-03-20 and disclosed publicly on 2026-04-08 as part of the Chrome 147 stable channel release. Affected versions include all Google Chrome releases prior to 147.0.7727.55, as well as Microsoft Edge (Chromium-based). Google assigned this a Chromium security severity of Low, while the CVSS v3.1 base score is 8.1 (High) (Chrome Release Blog, GitHub Advisory).
The root cause is improper input validation (CWE-20) in Chrome's WebML subsystem — the browser's implementation of the Web Neural Network API — which fails to adequately validate untrusted data supplied via HTML content. This allows an attacker to trigger an out-of-bounds memory write by serving a specially crafted HTML page to a victim. Exploitation requires user interaction (i.e., the victim must visit the malicious page), and no special privileges are required on the attacker's side. The Chromium bug tracker entry is issue #494341335, though full technical details remain restricted pending broad user update (Chrome Release Blog, GitHub Advisory).
Successful exploitation could result in browser crashes (denial of service), data corruption, or potentially arbitrary code execution within the browser's renderer process, depending on how the out-of-bounds write is leveraged. The CVSS scoring reflects high integrity and availability impact with no confidentiality impact, suggesting the primary risks are data corruption and application instability rather than direct data exfiltration. Because the vulnerability is confined to the browser sandbox, lateral movement to the underlying OS would require a separate sandbox escape (GitHub Advisory).
Google has patched this vulnerability in Chrome 147.0.7727.55 (Linux) and 147.0.7727.55/56 (Windows/Mac), released on April 7, 2026. Microsoft Edge (Chromium-based) users should apply the corresponding Edge update that incorporates the same fix. Users should enable automatic updates in Chrome (Settings → Help → About Google Chrome) to ensure the patch is applied promptly. No configuration-based workaround is available; updating to the patched version is the only remediation (Chrome Release Blog, Microsoft MSRC).
Coverage of CVE-2026-5915 was largely aggregated alongside the broader Chrome 147 security release, which addressed over 60 vulnerabilities including two Critical-severity WebML flaws (CVE-2026-5858 and CVE-2026-5859). Security news outlets such as GBHackers highlighted the overall Chrome 147 patch batch, noting the concentration of WebML-related issues. Community discussion was limited given the Low Chromium severity rating assigned to this specific CVE. No notable individual researcher commentary specific to CVE-2026-5915 has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."