CVE-2026-5872 is a use-after-free vulnerability in the Blink rendering engine of Google Chrome versions prior to 147.0.7727.55 that enables remote code execution within the browser sandbox through maliciously crafted HTML pages. This memory safety flaw allows attackers to exploit freed memory objects, potentially compromising the integrity of the affected system. The vulnerability carries a CVSS score of 8.8 (High severity) with a network-based attack vector requiring only user interaction and low attack complexity. The exploitation grants attackers high-level capabilities including confidentiality breach, integrity compromise, and availability disruption, though impacts are constrained to the Chrome sandbox environment. Current exploitation data indicates this vulnerability is not being actively exploited in the wild, as evidenced by its absence from the CISA Known Exploited Vulnerabilities catalog and its inactive status on threat intelligence hot lists. The EPSS score of 0.0014 reflects minimal exploitation likelihood compared to the broader CVE landscape, suggesting limited immediate risk despite the vulnerability's technical severity. Organizations should prioritize patching to Chrome 147.0.7727.55 or later, but this does not appear to require emergency response protocols at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 147.0.7727.55CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
>= 147.0.7727.55, < 147.0.7727.55CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.