CVE-2026-5877 is a use-after-free vulnerability in the Navigation component of Google Chrome versions prior to 147.0.7727.55 that permits remote code execution within the browser sandbox through a maliciously crafted HTML page. The vulnerability affects Chrome's core navigation functionality and represents a sandbox escape risk requiring user interaction to exploit. The vulnerability carries a CVSS v3.1 score of 8.8 (High), indicating significant risk with a network-based attack vector requiring no special privileges but user interaction to trigger. The attack has low complexity and yields high impact across confidentiality, integrity, and availability. However, the EPSS score of 0.001390 suggests relatively low real-world exploitation probability, placing it in the lowest percentile of vulnerability exploit likelihood. There is currently no evidence of active exploitation in the wild. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities catalog and shows no activity on exploit tracking platforms. Community attention remains minimal with a FAUCET risk score of 42.0 out of 100, indicating this should be prioritized as part of normal Chrome patching cycles but does not require emergency response protocols.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 147.0.7727.55CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
>= 147.0.7727.55, < 147.0.7727.55CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.