CVE-2026-5858Patch(apple / chrome)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apple chrome systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Heap buffer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 3d ago at 2 mentions (2026-04-09); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-04-09: 2Mentions · 2026-04-10: 1Mentions · 2026-04-12: 1Mentions · 2026-04-16: 1Patch / Workaround · 2026-04-09: 1Patch / Workaround · 2026-04-12: 1Patch / Workaround · 2026-04-16: 1Technical Details · 2026-04-09: 1Technical Details · 2026-04-10: 1Technical Details · 2026-04-12: 1Technical Details · 2026-04-16: 104-0904-1004-1204-16
Signal classification2 categories
Patch
360.0%
Disclosure
240.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-092
Disclosure1Patch1
2026-04-101
Disclosure1
2026-04-121
Patch1
2026-04-161
Patch1
Full discourse5 posts
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Patch

    💥CVE-2026-5858 – Google Chrome WebML heap buffer overflow (Critical): crafted HTML can corrupt heap memory and lead to arbitrary code execution in Chrome <147.0.7727.55. Patch to 147.0.7727.55/56 immediately. https://chromereleases.googleblog.com/2026/04/stable-channel-update-for-desktop.html #CVE20265858 #Chrome #WebML #RCE #AppSec #BrowserSecurity

    Post summary

    The tweet announces CVE-2026-5858, a critical Chrome WebML heap overflow vulnerability, and urges users to update to patched versions 147.0.7727.55/56 immediately.

    1002030
    1.5K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    There is a new vulnerability with elevated criticality in Google Chrome (CVE-2026-5858) https://vuldb.com/vuln/356456

    Post summary

    A new high‑criticality vulnerability (CVE‑2026‑5858) in Google Chrome has been identified, but the post provides no further technical or mitigation details.

    01010150
    2.1K followersView on X
  • iototsecnews@iototsecnews
    Patch

    Chrome 147 がリリース:Critical 脆弱性 CVE-2026-5858/5859 などを FIX https://iototsecnews.jp/2026/04/09/critical-chrome-vulnerabilities-let-attackers-to-execute-arbitrary-code/ 今回の Chrome アップデートで最も重要とされるのは、新しく導入された WebML (Web Machine Learning API) の実装における、データ処理時の不十分なメモリ境界チェックの修正にあります。具体的には、ヒープバッファ・オーバーフローの脆弱性 CVE-2026-5858 や、整数オーバーフローの脆弱性 CVE-2026-5859 といった、メモリ管理に関する深刻な不備が修正されています。これらの欠陥を悪用する攻撃者は、ユーザーに 悪意のWeb ページを閲覧させるだけで、ブラウザ・プロセス内での任意のコード実行を可能にします。速やかな、Chrome 147 へのアップデートが推奨されています。 #Chrome #CVE20265858 #CVE20265859 #Google #Vulnerability

    Post summary

    The post announces Chrome 147’s release, highlighting fixes for CVE‑2026‑5858/5859—heap buffer and integer overflows in WebML API—and urges users to update immediately.

    01000129
    484 followersView on X
  • ThreatLevel@ThreatLevelLabs
    Disclosure

    ⚫ Planned Fix Chrome WebML heap buffer overflow RCE 🔍 Details • No authentication required • Internet-facing deployment • Exploitable with default configuration • No active exploitation • No public PoC CVE-2026-5858 full analysis 👇 https://threatlevel.io/CVE-2026-5858

    Post summary

    The text announces a planned fix for CVE-2026-5858, describing a Chrome WebML heap overflow that allows RCE without authentication, but provides no PoC, exploit code, or evidence of active exploitation, and gives no patch specifics.

    00010121
    5 followersView on X
  • Abdulaziz Alharbi@Alharbi_Abz
    Patch

    متصفح كروم الاصدار 147 يحصل على تحديث لأكثر من 60 ثغرة اثنتين منها خطيرة في مكونات مثل : WebML - WebAudio- Skia تم اكتشافها من قبل باحثين مجهولين حصل كل واحد منهما على $43K . CVEs: heap buffer overflow (CVE-2026-5858) integer overflow (CVE-2026-5859) http://tinyurl.com/3kj9dn3b https://t.co/kquv8bPNKX

    Post summary

    The tweet announces that Chrome version 147 will be updated to patch more than 60 vulnerabilities, including two critical CVEs involving buffer overflows, indicating the availability of a patch.

    0000073
    582 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more