
⚡CVE-2026-5866 – Chrome Media use-after-free (High): UAF in the media pipeline means crafted media content can trigger memory corruption and arbitrary code execution. Fixed in 147. https://chromereleases.googleblog.com/2026/04/stable-channel-update-for-desktop.html #CVE20265866 #Chrome #Media #UseAfterFree #AppSec #ThreatIntel
Post summary
The post announces a high‑severity use‑after‑free bug in Chrome’s media pipeline (CVE‑2026‑5866) that allows memory corruption and arbitrary code execution, with a fix shipped in version 147 and no evidence of an active exploit or PoC.
