CVE-2026-5915
vulnerability analysis and mitigation

Overview

CVE-2026-5915 is an insufficient input validation vulnerability in the WebML component of Google Chrome that allows a remote attacker to perform an out-of-bounds memory write via a crafted HTML page. It was reported by ningxin.hu@intel.com on 2026-03-20 and disclosed publicly on 2026-04-08 as part of the Chrome 147 stable channel release. Affected versions include all Google Chrome releases prior to 147.0.7727.55, as well as Microsoft Edge (Chromium-based). Google assigned this a Chromium security severity of Low, while the CVSS v3.1 base score is 8.1 (High) (Chrome Release Blog, GitHub Advisory).

Technical details

The root cause is improper input validation (CWE-20) in Chrome's WebML subsystem — the browser's implementation of the Web Neural Network API — which fails to adequately validate untrusted data supplied via HTML content. This allows an attacker to trigger an out-of-bounds memory write by serving a specially crafted HTML page to a victim. Exploitation requires user interaction (i.e., the victim must visit the malicious page), and no special privileges are required on the attacker's side. The Chromium bug tracker entry is issue #494341335, though full technical details remain restricted pending broad user update (Chrome Release Blog, GitHub Advisory).

Impact

Successful exploitation could result in browser crashes (denial of service), data corruption, or potentially arbitrary code execution within the browser's renderer process, depending on how the out-of-bounds write is leveraged. The CVSS scoring reflects high integrity and availability impact with no confidentiality impact, suggesting the primary risks are data corruption and application instability rather than direct data exfiltration. Because the vulnerability is confined to the browser sandbox, lateral movement to the underlying OS would require a separate sandbox escape (GitHub Advisory).

Mitigation and workarounds

Google has patched this vulnerability in Chrome 147.0.7727.55 (Linux) and 147.0.7727.55/56 (Windows/Mac), released on April 7, 2026. Microsoft Edge (Chromium-based) users should apply the corresponding Edge update that incorporates the same fix. Users should enable automatic updates in Chrome (Settings → Help → About Google Chrome) to ensure the patch is applied promptly. No configuration-based workaround is available; updating to the patched version is the only remediation (Chrome Release Blog, Microsoft MSRC).

Community reactions

Coverage of CVE-2026-5915 was largely aggregated alongside the broader Chrome 147 security release, which addressed over 60 vulnerabilities including two Critical-severity WebML flaws (CVE-2026-5858 and CVE-2026-5859). Security news outlets such as GBHackers highlighted the overall Chrome 147 patch batch, noting the concentration of WebML-related issues. Community discussion was limited given the Low Chromium severity rating assigned to this specific CVE. No notable individual researcher commentary specific to CVE-2026-5915 has been identified.

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management