CVE-2026-5915

8.1

Google · Chrome

Google Chrome contains a memory corruption vulnerability in WebML due to insufficient input validation, which could allow a remote attacker to perform an out of bounds memory write.

Executive summary

A remote attacker can leverage an out of bounds memory write vulnerability in Google Chrome WebML to compromise system integrity via a crafted HTML page.

Vulnerability

This vulnerability is caused by insufficient validation of untrusted input within the WebML component. An unauthenticated remote attacker can trigger this flaw by enticing a user to visit a specifically crafted HTML page, resulting in an out of bounds memory write.

Business impact

Successful exploitation of this vulnerability allows an attacker to perform unauthorized memory operations, which can lead to application crashes or the potential for arbitrary code execution. Given the CVSS score of 8.1, this represents a significant risk to organizational endpoints, as the browser is a primary vector for web-based attacks that can lead to complete system compromise or data exfiltration.

Remediation

Immediate Action: Update all Google Chrome installations to version 147.0.7727.55 or later immediately to incorporate the necessary security patches.

Proactive Monitoring: Monitor browser-related logs and endpoint security telemetry for unusual process behavior or unexpected crashes that may indicate exploitation attempts.

Compensating Controls: Deploy endpoint protection platforms capable of detecting memory corruption patterns and ensure that browser sandboxing features remain fully enabled and configured correctly.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Organizations should prioritize the deployment of the latest Chrome browser updates across all managed devices. Because this flaw is triggered by user interaction with malicious web content, it is imperative to ensure that browser updates are applied globally to mitigate the risk of remote exploitation.

More Google CVEs

Sources