Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-5877

27
FAUCET Score

CVE-2026-5877 is a use-after-free vulnerability in the Navigation component of Google Chrome versions prior to 147.0.7727.55 that permits remote code execution within the browser sandbox through a maliciously crafted HTML page. The vulnerability affects Chrome's core navigation functionality and represents a sandbox escape risk requiring user interaction to exploit. The vulnerability carries a CVSS v3.1 score of 8.8 (High), indicating significant risk with a network-based attack vector requiring no special privileges but user interaction to trigger. The attack has low complexity and yields high impact across confidentiality, integrity, and availability. However, the EPSS score of 0.001390 suggests relatively low real-world exploitation probability, placing it in the lowest percentile of vulnerability exploit likelihood. There is currently no evidence of active exploitation in the wild. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities catalog and shows no activity on exploit tracking platforms. Community attention remains minimal with a FAUCET risk score of 42.0 out of 100, indicating this should be prioritized as part of normal Chrome patching cycles but does not require emergency response protocols.

Impacted Technologies

VendorProductVersion(s)CPE
< 147.0.7727.55CPE matchmatch criteria
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
>= 147.0.7727.55, < 147.0.7727.55CPE match
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.8HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.30%
Probability of exploitation in next 30 days
EPSS Percentile
22.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0030 is in the 27th percentile among its peer group of 14,875 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

microsoftpatch availablevia msrc
Product: Microsoft Edge (Chromium-based)Fixed in: 147.0.3912.60
googlevendor investigatingvia chrome_releases
View patch

Vendor Advisories (2)

microsoft2026-Apr/CVE-2026-5877

Chromium: CVE-2026-5877 Use after free in Navigation

Apr 2, 2026
googlegoogle:chrome-7d655429efb624cbCRITICAL

Stable Channel Update for ChromeOS / ChromeOS Flex

References

chromereleases.googleblog.com / 2026/04/stable-channel-update-for-desktop.html
Release NotesVendor Advisory
issues.chromium.org / issues/333024273
Permissions Required