CVE-2026-5919
vulnerability analysis and mitigation

Overview

CVE-2026-5919 is a low-severity vulnerability involving insufficient validation of untrusted input in the WebSockets component of Google Chrome. It was reported by Richard Belisle on 2026-02-10 and publicly disclosed on 2026-04-01 as part of the Chrome 147 stable channel release. The vulnerability affects all versions of Google Chrome prior to 147.0.7727.55, as well as Microsoft Edge (Chromium-based). It carries a CVSS v3.1 base score of 6.5 (Medium) (Chrome Releases, GitHub Advisory).

Technical details

The vulnerability is classified as CWE-20 (Improper Input Validation) and resides in Chrome's WebSockets implementation, where untrusted input is not adequately validated. Exploitation requires that an attacker has already compromised the renderer process — a significant precondition — after which a crafted HTML page can be used to bypass the Same Origin Policy (SOP) via malformed WebSocket communications. The attack vector is network-based, requires user interaction (e.g., visiting a malicious page), and no privileges are needed beyond the pre-existing renderer compromise. The Chromium issue tracker reference is #483423893 (Chrome Releases, GitHub Advisory).

Impact

Successful exploitation allows a remote attacker who has already compromised the renderer process to bypass the Same Origin Policy, potentially enabling unauthorized access to cross-origin data and resources. The primary impact is on integrity (CVSS integrity impact: High), with no direct confidentiality or availability impact assessed. Because exploitation requires a pre-compromised renderer, the practical risk is limited to chained attack scenarios where this vulnerability serves as a secondary step to escalate access or exfiltrate cross-origin data (GitHub Advisory, Chrome Releases).

Mitigation and workarounds

Google has addressed this vulnerability in Chrome 147.0.7727.55 (Linux) and 147.0.7727.55/56 (Windows/Mac), released on April 7, 2026. Users and administrators should update all Chrome instances to version 147.0.7727.55 or later immediately. Microsoft Edge (Chromium-based) users should also apply the corresponding Edge update. No specific configuration-based workaround is available; upgrading is the only recommended remediation (Chrome Releases, Microsoft MSRC).

Community reactions

The vulnerability was covered as part of broader reporting on the Chrome 147 update, which patched over 60 vulnerabilities including two critical WebML flaws. Security outlets such as GBHackers and BeyondMachines noted the scale of the Chrome 147 security release, though CVE-2026-5919 itself received limited individual attention given its Low severity rating and exploitation preconditions. The SANS Internet Storm Center also logged the update in its diary (Chrome Releases).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management