CVE-2026-5859Patch(apple / chrome)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apple chrome systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Integer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-472

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Peaked 1d ago at 1 mentions (2026-04-12); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-12: 1Mentions · 2026-04-16: 1Patch / Workaround · 2026-04-12: 1Patch / Workaround · 2026-04-16: 1Technical Details · 2026-04-12: 1Technical Details · 2026-04-16: 104-1204-16
Signal classification1 categories
Patch
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • iototsecnews@iototsecnews
    Patch

    Chrome 147 がリリース:Critical 脆弱性 CVE-2026-5858/5859 などを FIX https://iototsecnews.jp/2026/04/09/critical-chrome-vulnerabilities-let-attackers-to-execute-arbitrary-code/ 今回の Chrome アップデートで最も重要とされるのは、新しく導入された WebML (Web Machine Learning API) の実装における、データ処理時の不十分なメモリ境界チェックの修正にあります。具体的には、ヒープバッファ・オーバーフローの脆弱性 CVE-2026-5858 や、整数オーバーフローの脆弱性 CVE-2026-5859 といった、メモリ管理に関する深刻な不備が修正されています。これらの欠陥を悪用する攻撃者は、ユーザーに 悪意のWeb ページを閲覧させるだけで、ブラウザ・プロセス内での任意のコード実行を可能にします。速やかな、Chrome 147 へのアップデートが推奨されています。 #Chrome #CVE20265858 #CVE20265859 #Google #Vulnerability

    Post summary

    Chrome released version 147 to fix critical heap buffer and integer overflows (CVE‑2026‑5858/5859) that enable arbitrary code execution on malicious web pages; users are strongly urged to update immediately.

    01000129
    484 followersView on X
  • Abdulaziz Alharbi@Alharbi_Abz
    Patch

    متصفح كروم الاصدار 147 يحصل على تحديث لأكثر من 60 ثغرة اثنتين منها خطيرة في مكونات مثل : WebML - WebAudio- Skia تم اكتشافها من قبل باحثين مجهولين حصل كل واحد منهما على $43K . CVEs: heap buffer overflow (CVE-2026-5858) integer overflow (CVE-2026-5859) http://tinyurl.com/3kj9dn3b https://t.co/kquv8bPNKX

    Post summary

    Chrome version 147 has been updated to address over 60 vulnerabilities, including two serious buffer overflows (CVE-2026-5858 and CVE-2026-5859) discovered by researchers, with the update acting as a patch.

    0000073
    582 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more